All Apps and Add-ons

question regarding aggregation with Splunk/Servicenow

multiverse
Engager

Hi Ron,

I am a neophyte to both Splunk and Servicenow. I have installed your app, and ran a few examples. Works great, nice job. It has fallen to me to integrate the two, and so far so good. But I am stuck on understanding how to leverage your app in regards to aggregate. There is is precious little knowledge, and I assume this is something I should know, but don't. Could you offer a novice explanation with a couple of novice examples please?

Thanks!

0 Karma

Ron_Naken
Splunk Employee
Splunk Employee

There doesn't appear to be much information on how to use aggregate functions for ServiceNow, after glancing through the ServiceNow wiki. There are examples of how to use some of the aggregate functions (i.e. SUM, AVG, COUNT, MIN, MAX) with "having" and "group by" clauses. Here's a link to the wiki that describes aggregates and provides examples:

http://wiki.servicenow.com/index.php?title=Direct_Web_Service_API_Functions

The in-app help for the ServiceNow app provides an example of how to use aggregates within Splunk. Note that you will also need to activate the Aggregate Web Services Plug-In in your ServiceNow portal:

http://wiki.servicenow.com/index.php?title=Activating_ServiceNow_Plugins
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...