Getting Data In

Integration with service now

mokshubajaj
New Member

Can Splunk be integrated with service now

Tags (1)
0 Karma
1 Solution

ccsfdave
Builder

Have you seen the app: http://apps.splunk.com/app/1228 ? I am sorta in the same boat looking for how our new implementation of Service Now will be best consumed by Splunk. If you need it and when I find more, I would be more than happy to share

View solution in original post

desoto-chan
Explorer

yep, it can be integrated.  it's mostly used for events/incidents. look at the docs here: Configure ServiceNow to integrate with the Splunk platform - Splunk Documentation for further details (+ there are also video tutorials). I've used it, worked perfectly. in case you seek additional help (an external one) - there are plenty of tools available on the market to connect the systems. tools like trayio and zigiosp can help you, too. I've used them both. but I'm current using the latter for such instances.

0 Karma

SanthoshKandadi
New Member

How to get the garbage values to display the actual values for fields assigned_to assignment_user_username?

0 Karma

ccsfdave
Builder

@a2ay Actually those "garbage" values are the system numbers that correspond to the users of the system. I thought this was true but verified it by looking at index=snow |table assigned_to assignment_user_username

Let me know if you agree.

0 Karma

a2ay
New Member

yeap integration done..the only thing that issue have with receiving fields...for example in these fileds in splunk app "opened_by, assigned_to, resolved_by" getting garbade value like 864b0ae40fc12500ce8a5bd69asas.

0 Karma

dbourg_splunk
Splunk Employee
Splunk Employee

@bwindham, We've posted a new app that is quite easy to use. The setup is accomplished via the GUI (or manually edit the conf files if you prefer). You can find it here:

0 Karma

a2ay
New Member

can you let me know how it need to be configured to get all the required tables of snow in Splnukapp?

0 Karma

bwindham
Path Finder

Did you get Splunk to integrate with your Service Now instance? I am at that point now. I have added the app, created a user in SN and given SOAP roles, added the user login/password in passwd.conf and tried manually. Command I am running is "snow instance=.service-now.com request=incident action=query".

But I continue to get no results.
Any help would be appreciated.

0 Karma

ccsfdave
Builder

Unfortunately, we are still in UAT testing so there is no implementation yet. When we do, which should be w/in a week or two, I will post on our experience

0 Karma

ccsfdave
Builder

I doubt 3 yr later this is still an issue but seriously, that is how long it took us to finally integrate they systems.

0 Karma

ccsfdave
Builder

Have you seen the app: http://apps.splunk.com/app/1228 ? I am sorta in the same boat looking for how our new implementation of Service Now will be best consumed by Splunk. If you need it and when I find more, I would be more than happy to share

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...