All Apps and Add-ons

Splunk integration with ServiceNow case management?

ravitejat
New Member

I have integrated Splunk with Service Now using Add on. Now I have 2 questions:

  1. I'm able to bring the desired cases data into Splunk. I'm only able to create but cannot delete the record in Splunk when I delete the same case in Service now , so what should I do?
  2. When trying to push the data to ServiceNow from Splunk, I'm able to push the data to only incident and event table, but not my desired table. Is there a way to do that?
0 Karma

rjv
New Member

For point 2, yes , if from UI like alert configuration screen, mention the ServiceNow table name in the 'endpoint' . if from a custom search, along with minimum parameters Account and Correlation_ID , add 'scripted_endpoint' , e.g.  | eval scripted_endpoint="/api/now/table/xxxxxx" 
Refer Splunk documentation: Commands, alert actions, and scripts - Splunk Add-on for ServiceNow

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...