All Apps and Add-ons

ServiceNow MID Server for Event Integration

adzs
Engager

I'm looking to send events from Splunk to ServiceNow using the add-on.
The catch is, for security reasons, we may be required to push the data from Splunk to ServiceNow via a MID Server.

Normal approach:
Splunk -> ServiceNow

Possible approach required for the client:
Splunk -> MID Server -> ServiceNow

Does the add-on support sending the event to the MID server at all? If not, what are the alternative options available?

Roy_9
Motivator

if that MID server supports Snow API and there should be some scripted alert action to send data, it should work i guess.

Basically in the Event integration configuration, you need to provide node details.

If you want to send the events as an incident you should provide API details as below.

/api/now/table/incident

0 Karma

lmcgchr
New Member

Hi,

Is your Splunk environment a SaaS environment? 

I was told that for Splunk On-prem, you need to use the MId server.

Thanks

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...