By default Splunk collects a years worth of data from ServiceNow. Apart from the since_when attribute in inputs.conf / changing the default date through UI, is there a way to dynamically say - collect data two days prior to current time?
Put ignoreOlderThan = 2d
in your inputs.conf file stanza for the Service Now logs, and that will cap how far back it will look in the logs. You can also use other time values, such as 48h