All Apps and Add-ons

ServiceNow MID Server for Event Integration

adzs
Engager

I'm looking to send events from Splunk to ServiceNow using the add-on.
The catch is, for security reasons, we may be required to push the data from Splunk to ServiceNow via a MID Server.

Normal approach:
Splunk -> ServiceNow

Possible approach required for the client:
Splunk -> MID Server -> ServiceNow

Does the add-on support sending the event to the MID server at all? If not, what are the alternative options available?

Roy_9
Motivator

if that MID server supports Snow API and there should be some scripted alert action to send data, it should work i guess.

Basically in the Event integration configuration, you need to provide node details.

If you want to send the events as an incident you should provide API details as below.

/api/now/table/incident

0 Karma

lmcgchr
New Member

Hi,

Is your Splunk environment a SaaS environment? 

I was told that for Splunk On-prem, you need to use the MId server.

Thanks

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...