Getting Data In

How can I onboard SNOW RITM variables data to splunk

epari1437
Engager

Requirement is to onboard SNOW RITM variables data to Splunk. Using table name SC_REQ_ITEM and SC_TASK, I can able to fetch data except variables.

Can anyone suggest how can I fetch data for variables which are linked to the catalog item/task.

 

My event would be :

You are requesting for: value

your name: value

select system: laptop

epari1437_0-1623931002717.png

 

0 Karma

ismedley
Engager

Splunk's add-on for ServiceNow would do this for you - you'd need to manually edit its inputs.conf to create an ingestion for the sc_req_item table as that one isn't included out the box.

Failing that, the add-on creates a query of the format 

https://<????>.service-now.com/api/now/table/sc_req_item?sysparm_display_value=all&sysparm_offset=0&...timestamp>^sys_updated_on%3C<later_timestamp>^ORDERBYsys_updated_on,sys_id

which will resolve the lookup fields for the record.  The sysparm_fields parameter can be used to restrict the fields returned

 

Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...