The current version of SplunkTAsnow 3.1 does not include adaptive response actions.
It might be something introduced in a later version (a new release is due any time now to support the latest SNOW platform), however I suspect Phantom would be a more "supportable" approach for the future
Then I'll have to purchase Phantom, and provision hardware for that also, or have I missunderstood the licenzing and deployment options.
I must admit, I haven't really lokked into phantom yet.
Maybe - maybe not.
You can still use the alert framework to raise service now tickets/incidents (using SplunkTAsnow), just not as adaptive response actions.
With regard to Phantom - yes it is a separate product and licence. I have no experience with it, so cant really comment on how it works.
The ServiceNow alert actions should already be available to be triggered as adaptive response actions from correlation searches, provided that the permissions are set correctly so that the ServiceNow alert actions are available to all apps. However, in order to get them to appear as an option as an ad-hoc adaptive response from the Incident Review dashboard, you'll need the param._cam, which you can add on your own instance:
Follow the docs to do this here: http://dev.splunk.com/view/enterprise-security/SP-CAAAFBG