All Apps and Add-ons

ServiceNow addon capture login info including src ip?

ebaileytu
Communicator

I have been asked to capture user login information from our SN instance and I am not sure how to get that data into Splunk. I have the SN add-on installed and I see lots of audit information once someone logs in, but I do not see login info such as username, success or failure and src ip. Can that info be pulled into Splunk? Any idea how?

Thanks!

0 Karma
1 Solution

ebaileytu
Communicator

for anyone interested you can get this information by turning on access to syslog_transaction table in the SN add-on inputs section under inputs. Ne warned it is a lot of data and you can only pull 1000 events per collection interval so plan accordingly.

View solution in original post

0 Karma

ebaileytu
Communicator

for anyone interested you can get this information by turning on access to syslog_transaction table in the SN add-on inputs section under inputs. Ne warned it is a lot of data and you can only pull 1000 events per collection interval so plan accordingly.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...