Splunk Enterprise Security

Multiple incident creation on servicenow through splunk

yashaswinig2210
Engager
Hi All, @renjith_nair
 
I'm working on a requirement to create a Splunk Alert which triggers/Creates the Incident in Service Now portal.
I want the alert to create multiple incidents for each result.
My Findings : The alert creates Single Incident with multiple events for each result in ServiceNow.
Requirement : Alert should be able to create Incident for each result in ServiceNow.
How can this be achieved?
Labels (1)
0 Karma

rajashekar_s
Path Finder

After creating the correlation search and alert action to be service now incident,

goto setting-> search,reports and alerts, find you search. Click on it, scroll down and change the trigger to each result from once and it should create one incident per row of your result

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...