All Apps and Add-ons

Installing a forwarder on ServiceNow

jclehmuth
Path Finder

I have been tasked to "integrate" ServiceNow with a Splunk instance. We have a server where Splunk is installed and there is a separate machine where ServiceNow is installed. The people that are requesting this want to use the ServiceNow app. I have no experience with ServiceNow. I installed a universal forwarder on the ServiceNow server. So I hvae a couple questions...
Does the app still work with a forwarder? Or should I install a regular Splunk instance on the ServiceNow server and forward it to my regular search head?

Thanks in advance.

0 Karma

philparker
Engager

Hi,

We have just build just that and so much more. SkyFormation Extend (c) for Splunk extracts security events from multiple
business cloud applications (e.g. Salesforce, Google App, ServiceNow, Office 365,AWS,...) and transforms them to unified and actionable events sent to your Splunk or other SIEM solution.

No more cloud applications integration or classification worries, and all in unified form for easiest correlations and investigation across apps.

SkyFormation is a Java app you can install at on-premise on any machine you want, and it will take you 5 minutes to set it up.

Please have a look at:
https://splunkbase.splunk.com/app/2932/

Feel more then welcome to ask me any question at [email protected]

Best
Phil
www.skyformation.com

piebob
Splunk Employee
Splunk Employee

The Splunk for ServiceNow add-on is just a custom search command ("snow") for your users to use.

you should install the add-on on the Splunk host your users are using for searching (if they're using a search head, install it there), and install the universal forwarder on the ServiceNow server (as you've done) and forward the ServiceNow logs to your main Splunk instance.

unrelated, but there are some notes in the Documentation tab for the ServiceNow add-on that might be useful for your users:
http://apps.splunk.com/app/1228/

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...