Dear Splunkers,
Does splunk ES( when purchased) comes with any build-in ticket management system or one has to buy a new ticketing system for incident management?.
We have Manageengine ticket system deployed in over environment however we are not much sure whether it will fully integrate with splunk or we would have to hire a developer for its integration.
ES does have a basic ticketing system built-in. As many as not use some other more fully-featured ticketing system like ServiceNow or JIRA. We have done many integrations for clients to have Splunk/ES create tickets in 3rd-party systems. There are apps that help, too.
ES does have a basic ticketing system built-in. As many as not use some other more fully-featured ticketing system like ServiceNow or JIRA. We have done many integrations for clients to have Splunk/ES create tickets in 3rd-party systems. There are apps that help, too.
Is serviceNow free or paid?
Hi.
Could you provide more information or links about this feature,, in-built ticketing system..
Regards
Do you have the documentation that helps explain what features and functions the internal ticket management systems has? Also how much can be changed like escalations, notifications, attached files, etc.
You could use the investigation workbench. It's like ticket tracking & collaborating on investigations for assets, identities, or artifacts involved in a potential security incident:
https://docs.splunk.com/Documentation/ES/6.4.0/User/InvestigationWorkbench
Thanks woodcock,