Splunk Search

Splunk ServiceNow Integration "snowincident" Command

michaelsplunk1
Path Finder

Hi Everyone!

Does the "snowincident" command always create an incident upon being called? I want to use this in an alert, so that we use the "custom_fields" setting, however, we only want the incident to be created if the alert was triggered.

Thanks!

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Get More Out of Your Security Practice With a SIEM

Get More Out of Your Security Practice With a SIEMWednesday, July 31, 2024  |  11AM PT / 2PM ETREGISTER ...

New This Month - SLO Capabilities, APM Advanced Filtering & Usage Analytics Plus ...

More for SLO Management We’re continuing to expand the built-in SLO management experience in Splunk ...

Enterprise Security Content Update (ESCU) | New Releases

In June, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security ...