Hi Splunk Community,
I was wondering if anyone might be able to provide some advice around using the ServiceNow add-on for Splunk specifically in regards to the consuming data from the CMDB.
There are OOB Inputs that come with the add-on which are fine for some basic tables however I'm looking at the CI relationship table which currently contains 19m+ records! We don't want to consume all of those as we're only really interested in the ones that relate to the basic tables we're already importing using the OOB inputs, which is around 10 tables.
The filters available with the add-on don't provide enough functionality to filter our requirement. Maybe a custom REST API call not within the ServiceNow add-on or maybe a post from ServiceNow to Splunk is the way to go. Keen to hear how others might have tackled anything similar?