Splunk Search

Splunk ServiceNow Integration "snowincident" Command

michaelsplunk1
Path Finder

Hi Everyone!

Does the "snowincident" command always create an incident upon being called? I want to use this in an alert, so that we use the "custom_fields" setting, however, we only want the incident to be created if the alert was triggered.

Thanks!

Labels (1)
0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!