All Apps and Add-ons

Splunk Add-on for ServiceNow: How to troubleshoot why data is not being pulled from ServiceNow?

amitag
New Member

Hi All,

We are integrating Splunk with Service Now. Till now we have followed below steps:

  • Installed Splunk Add-on for ServiceNow on our Splunk instance
  • Entered service now configuration and proxy details to setup connection with Service Now
  • Created new index with incident table of service now
  • scheduled the index to refresh data after every 120 secs

After all these steps, we are still are able to pull the data from Service Now using the index and getting below error -

HttpListener - Socket error from 127.0.0.1 while accessing /servicesNS/nobody/Splunk_TA_snow/apps/local/Splunk_TA_snow/setup: Winsock error 10053 
Encountered the following error while trying to update: Splunkd daemon is not responding: (u"Error connecting to /servicesNS/nobody/Splunk_TA_snow/apps/local/Splunk_TA_snow/setup: ('The read operation timed out',)",)

What could be the possible reason for this kind of error and how can we verify that we have successfully made the connection with Service Now?

What could be the further steps to resolve this issues.

Appreciate your help on this issue....

Regards,
Amit

0 Karma

srikanth1213
Path Finder

It was resolved once we changed the account credentials for Splunk Add-on for ServiceNow.

0 Karma

surekhasplunk
Communicator

Setup page itself is not coming its throwing error "Page not found"

0 Karma

srikanth1213
Path Finder

you might want to check in ta_snow.logs to find more info ..

0 Karma

srikanth1213
Path Finder

@ surekhasplunk : Is the issue resolved ? if so , can you share with us the solution...

0 Karma

surekhasplunk
Communicator

Yes its resolved once I moved from windows local splunk to cloud Linux splunk.
Also if you are sticking to windows you can try below steps:
1) Delete all the apps related to splnk add on TA for service now and service now app for splunk if you have installed.
2) Delete the indexes but not snow.dat
3) Run -> cmd -> right click open as administrator -> then go to splunk bin path and restart splunk
4) Now the set up page should appears as expected and incident data also gets populated.

0 Karma

srikanth1213
Path Finder

Ok thank you.

0 Karma

ravitejat
New Member

Can any one please help me step by step integration, after that how to pull and push the data from Splunk? I'm new to Splunk and it's my first project to integrate service now with splunk, please help?

0 Karma

srikanth1213
Path Finder

We received the exact same error and the issue got fixed by itself ..I have raise a support ticket on the same. In the mean time can you please tell us how it got fixed at your end ?

0 Karma

dinokurian
New Member

It looks like a permission issue that Splunk doesn't have the required permission to pull the data from Service now tables.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...