All Apps and Add-ons

ServiceNow MID Server for Event Integration

adzs
Engager

I'm looking to send events from Splunk to ServiceNow using the add-on.
The catch is, for security reasons, we may be required to push the data from Splunk to ServiceNow via a MID Server.

Normal approach:
Splunk -> ServiceNow

Possible approach required for the client:
Splunk -> MID Server -> ServiceNow

Does the add-on support sending the event to the MID server at all? If not, what are the alternative options available?

Roy_9
Motivator

if that MID server supports Snow API and there should be some scripted alert action to send data, it should work i guess.

Basically in the Event integration configuration, you need to provide node details.

If you want to send the events as an incident you should provide API details as below.

/api/now/table/incident

0 Karma

lmcgchr
New Member

Hi,

Is your Splunk environment a SaaS environment? 

I was told that for Splunk On-prem, you need to use the MId server.

Thanks

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...