All Apps and Add-ons

Splunk Addon for Service Now-dump out all ServiceNow addon setup for each alert

Cheng2Ready
Communicator

Splunk is there a way to dump out all ServiceNow add on setup for each/all alert?
trying to grab all alerts that has this action
and put in a table with all the setup it has :
state, CI, contact  type, assignment group ,....ect

 

Cheng2Ready_1-1738776279789.pngCheng2Ready_2-1738776289656.png

 

Labels (2)
0 Karma
1 Solution

luizlimapg
Path Finder

Hi @Cheng2Ready 

You can use REST for that, like in this example:

| rest /servicesNS/-/-/saved/searches splunk_server=local
| search action.snow_incident=1
| table title, disabled, action.snow_incident.param.assignment_group, action.snow_incident.param.contact_type

The fields related to the alert actions in ServiceNow follow the pattern action.snow_event* or action.snow_incident*

View solution in original post

luizlimapg
Path Finder

Hi @Cheng2Ready 

You can use REST for that, like in this example:

| rest /servicesNS/-/-/saved/searches splunk_server=local
| search action.snow_incident=1
| table title, disabled, action.snow_incident.param.assignment_group, action.snow_incident.param.contact_type

The fields related to the alert actions in ServiceNow follow the pattern action.snow_event* or action.snow_incident*

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Maximizing the Value of Splunk ES 8.x

Splunk Enterprise Security (ES) continues to be a leader in the Gartner Magic Quadrant, reflecting its pivotal ...