Splunk Enterprise Security

Multiple incident creation on servicenow through splunk

yashaswinig2210
Engager
Hi All, @renjith_nair
 
I'm working on a requirement to create a Splunk Alert which triggers/Creates the Incident in Service Now portal.
I want the alert to create multiple incidents for each result.
My Findings : The alert creates Single Incident with multiple events for each result in ServiceNow.
Requirement : Alert should be able to create Incident for each result in ServiceNow.
How can this be achieved?
Labels (1)
0 Karma

rajashekar_s
Path Finder

After creating the correlation search and alert action to be service now incident,

goto setting-> search,reports and alerts, find you search. Click on it, scroll down and change the trigger to each result from once and it should create one incident per row of your result

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...