It’s worth noting that this issue is being tested under the Splunk application for OS X. The goal is to get Splunk creating tickets in Service Now based on scheduled alerts. My working example is a WARN when a disk crosses the threshold of 20% available.
The search I have scheduled in Splunk looks like this:
index=* sourcetype=df | multikv | eval perc_used=trim(UsePct, "%") | search perc_used >= 80
I have put the rest of the gory details here so as not to abuse this forum:
Thank you very much