Other Usage

Invalid end point for ServiceNow integration

KeithH
Communicator

Hi,  I have installed the "ServiceNow Security Operations Event Ingestion Addon for Splunk Enterprise" app and configured it using Basic Auth.
When I try to send an event I get error:
   command="snsecingest", Unable to forward notable event 

after putting some logging in the python I can see the error behind that is 

{"error":{"message":"Requested URI does not represent any resource","detail":null},"status":"failure"}

Even a simple curl straight to the endpoint fails with the same error.

Does anyone know if this endpoint (supplied with the app) might have changed or does it need to be created for each domain?
Endpoint I have is:

https://XXXXXXdev.service-now.com/api/sn_sec_splunk_v2/event_ingestion

  Any suggestions would be appreciated.
Thanks

0 Karma
1 Solution

manjunathmeti
Champion

Hi @KeithH,

Did you configure Service Now to integrate with your Splunk? If not, you can refer to this: https://docs.splunk.com/Documentation/AddOns/released/ServiceNow/ConfigureServiceNowtointegratewithS....

View solution in original post

manjunathmeti
Champion

Hi @KeithH,

Did you configure Service Now to integrate with your Splunk? If not, you can refer to this: https://docs.splunk.com/Documentation/AddOns/released/ServiceNow/ConfigureServiceNowtointegratewithS....

KeithH
Communicator

Hi @manjunathmeti 

thanks for the suggestion but why would I do that. 
The link you sent relates to app the "Splunk Add-on for ServiceNow"

whereas I am using the app "ServiceNow Security Operations Event Ingestion Addon for Splunk Enterprise"

Thanks

0 Karma

manjunathmeti
Champion

The link was just for reference, usually, you need to deploy an app or integration in Service Now first so that the add-on on Splunk integrates with Service Now.

KeithH
Communicator

Ah that makes sense - thanks @manjunathmeti 

I will hassle my servicenow contact and see if I can understand what he has done

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...