All Apps and Add-ons

Splunk add-on for servicenow - additional fields

ADRIANODL
Explorer

Hi all,
We've just installed the Splunk Add-on for ServiceNow on our Splunk Cloud instance, which enables integration between the the two platforms.
The integration itself worked well, and alerts have been successfully configured to trigger an incident in Service Now. However, the ServiceNow Incident Integration add-on comes with a limited number of fields (state, CI, Contact Type, Assignment Group, Category, Subcategory, Short Description, Correlation ID), which doesn't pre-populate the incident with enough information for our teams to work on the incidents. Whenever an incident is triggered, they need to log on to splunk cloud to see more details about the incident.

My question is: is there a way to add additional fields to the ServiceNow Incident Integration add-on, such as severity, long description, etc)?

Thank you for your responses in advance.

Adriano

koshyk
Super Champion

Can you please check if this is still the case? With new version of SNOW and addon, we are getting all extra data

0 Karma

ChrisBell04
Communicator

@koshyk - what new version? Splunk Add-on for ServiceNow Version 3.1.0 was last updated April 6, 2018.

For what its worth, there has been no communication about enhancement request ADDON-17893 either.

0 Karma

koshyk
Super Champion

sorry I meant the ServiceNow version too. Jakarta/London versions are emitting too much data, especially fields starting with dv_*
We are receiving about 60+ fields for incident table

0 Karma

ChrisBell04
Communicator

Enhancement request ADDON-17893 has been filed to add the Description field to incident creation.

tommoore
Path Finder

What's the status on this?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...