thank you so much. The Splunk_TA_snow works in my machine 🙂
but there is another question, I would like to specify the "display_value" for each ticket type.
I set "display_value = all" in service_now.conf, specify fields in inputs.conf like below, but still get all fields of incident_sla. how can I do that? thanks!
display_value = inc_closed_at,inc_state,inc_number,inc_cmdb_ci,inc_priority,inc_category,inc_u_region
... View more