Splunk Search

create ticket in service now - arguments missing

multiverse
Engager

It’s worth noting that this issue is being tested under the Splunk application for OS X. The goal is to get Splunk creating tickets in Service Now based on scheduled alerts. My working example is a WARN when a disk crosses the threshold of 20% available.

The search I have scheduled in Splunk looks like this:

index=* sourcetype=df | multikv | eval perc_used=trim(UsePct, "%") | search perc_used >= 80

I have put the rest of the gory details here so as not to abuse this forum:

http://themap.multiverse.org/snow_alert-sh-does-not-create-service-now-ticket-when-scheduled-under-s...

Thank you very much

Tags (1)
0 Karma

ashish_test
New Member

Link Provided is not displaying contents. Error 404:Page not found !
Can you please share the information about how we can create the tickets in servicenow using splunk.

0 Karma

jonuwz
Influencer

I've read the link. How are you authenticating within the snow script when its called from an alert ? When you run it from the CLI it looks like you need to enter a username / password.
Also - what arguments do you think are missing ? Have you added debug to the script and redirected it to file to see where i tgoes wrong ?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...