Splunk Enterprise Security

Splunk Add-on for ServiceNow configuration

New Member

Looking for some assistance with an error that I am receiving when I try and configure the Splunk add-on for ServiceNow from Splunk base.
When setting up the "ServiceNow account" information - Add ServiceNow Account in the Splunk Web interface, I receive the following error.
ERROR: Unable to reach server at https://InstanceName.service-now.com. Check configurations and network settings.

Account has been created in ServiceNow with the following roles
import_transformer, rest_api_explorer, sn_sec_splunk_v2.api_account_access, sn_si.analyst, sn_si.integration_user, soap

URL has been verified as the "Base URL" to the instance
User name and password have been verified by the ServiceNow team. Password has been reset and retested as well to ensure accuracy

alt text

0 Karma


check this link with information about how you can setup the proxy and edit the configuration from CLI.
you have to edit the service_now.conf at $SPLUNK_HOME/etc/apps/Splunk_TA_snow/local. If the file is not under local folder, you can copy the service_now.conf from default to local and run the proper configuration


0 Karma

Splunk Employee
Splunk Employee

Make sure you have not configured any proxy settings. Try to ping the URL if it accessible or not from the server you are trying to configure.

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...