All Apps and Add-ons

Splunk automatically escaping the backslash character when creating/updating a snow ticket

michael3
Explorer

I'm trying to set the Description field of a ServiceNow Incident ticket through Splunk, and the string I'm passing contains a newline (\n).  But when Splunk creates/updates the ticket, either through the snowincident command or an action alert, it will automatically escape the backslash character.   So after Splunk passes the info to snow, the underlying json of the ticket looks like this:

{"description":"this is a \\n new line"}


and my Description field looks like this:

this is a \n new line

Is this something that Splunk is doing, or the ServiceNow Add-On?  Does anyone know of a way to get around this?

Labels (2)
0 Karma

magg
Observer

Also requesting a working way of adding newline to description in a servicenow incident generated by this addon

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...