All Apps and Add-ons

ServiceNow MID Server for Event Integration

adzs
Engager

I'm looking to send events from Splunk to ServiceNow using the add-on.
The catch is, for security reasons, we may be required to push the data from Splunk to ServiceNow via a MID Server.

Normal approach:
Splunk -> ServiceNow

Possible approach required for the client:
Splunk -> MID Server -> ServiceNow

Does the add-on support sending the event to the MID server at all? If not, what are the alternative options available?

Roy_9
Motivator

if that MID server supports Snow API and there should be some scripted alert action to send data, it should work i guess.

Basically in the Event integration configuration, you need to provide node details.

If you want to send the events as an incident you should provide API details as below.

/api/now/table/incident

0 Karma

lmcgchr
New Member

Hi,

Is your Splunk environment a SaaS environment? 

I was told that for Splunk On-prem, you need to use the MId server.

Thanks

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

March Community Office Hours Security Series Uncovered!

Hello Splunk Community! In March, Splunk Community Office Hours spotlighted our fabulous Splunk Threat ...

Stay Connected: Your Guide to April Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars in April. This post ...