are you talking about the ids?
If you want to enrich the id with actual namess, check out section "Collect display values directly from the API"
http://docs.splunk.com/Documentation/AddOns/released/ServiceNow/Troubleshooting
if you you are getting values that are not expected, try to access the data manually outside of Splunk to confirm that it is not a splunk issue. for that check out the "missing data" (same steps apply here) of http://docs.splunk.com/Documentation/AddOns/released/ServiceNow/Troubleshooting
... View more