Splunk Enterprise Security

Multiple incident creation on servicenow through splunk

yashaswinig2210
Engager
Hi All, @renjith_nair
 
I'm working on a requirement to create a Splunk Alert which triggers/Creates the Incident in Service Now portal.
I want the alert to create multiple incidents for each result.
My Findings : The alert creates Single Incident with multiple events for each result in ServiceNow.
Requirement : Alert should be able to create Incident for each result in ServiceNow.
How can this be achieved?
Labels (1)
0 Karma

rajashekar_s
Path Finder

After creating the correlation search and alert action to be service now incident,

goto setting-> search,reports and alerts, find you search. Click on it, scroll down and change the trigger to each result from once and it should create one incident per row of your result

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...