All Apps and Add-ons

How to use ServiceNow data to link back to other Splunk data?

thefuzz4
Path Finder

So we have our Splunk instance ingesting everything from ServiceNow. I have some dashboards that track when a service such as tomcat/weblogic etc are shut down. Now I want to be able to accomplish the following things:

I need to be able to link the log data back to the ServiceNow data for that event to show tickets that were created as a result of this, as well as show how much time was spent to fix this problem.

I wrote this search

index=* NOT sourcetype=wls9_managedserver NOT sourcetype=weblogic_access host=*prod* CASE("Server state changed to FAILED") OR CASE("Fatal Error at WriteHandler") OR CASE("Server state changed to SHUTDOWN") OR CASE("Destroying ProtocolHandler") OR CASE("Server startup in*")  sourcetype=weblogic_domain_out
| join type=inner max=0 domain
[
search index=app eventtype=snow_incident domain]

I replaced the actual domain name with domain 🙂

So I'm hoping to be able to get this rolling and enhance my splunkfu in the process. Thank you all in advance for your help with this.

0 Karma

koshyk
Super Champion

hi,
Hope you are familiar with Common Information Model (CIM) ? If yes, please download "Service Now Addon" . This will normalise all SNOW fields to CIM standards and will map to "Ticket Management" model. (All_ticket_management -> dest would be your affected CI for example) Also you can use "ServiceNow" cmdb_ci for asset management. Would strongly advise once your environment grows to use CIM standards for all logs if possible and mapping will be a quite easy task

0 Karma

thefuzz4
Path Finder

Yes we are using the addon to pump all of the data from service now into splunk already. So it is all CIM compliant. Thanks.

0 Karma

koshyk
Super Champion

Cool. I'm not that familiar with web logic, but in websphere add-on you can use "dest" to match "dest" of service now.

0 Karma

thefuzz4
Path Finder

So yeah how do I match one portion of a search to another portion? The other thing I don't understand is that the event_type from service now only seems to work inside of the service now app inside of splunk.

0 Karma

koshyk
Super Champion

You can use join, something like..

index= xyz sourcetype=abc | join type=left dest [ search index=snow index dest=* | dedup dest ]
0 Karma

thefuzz4
Path Finder

Excellent thank you @koshyk Going to give it a whirl now.

0 Karma

thefuzz4
Path Finder

Ok so I apologize about my delay in getting back to you been tied up with other issues.

So here is what I have for a search but its only returning from one index and not both.

index=weblogic sourcetype=weblogic_out  | join type=left host [ search index=app eventtype=snow_incident short_description=* | dedup host ]

trying to join on the host name because the host name is in the short_description field that is returned from snow

0 Karma

koshyk
Super Champion

You r putting only one index. You could put index=web logic OR index=another index

0 Karma

Jeremiah
Motivator

Are you asking for help with improving the search? Maybe you can give an example of each type of event you are planning to correlate.

0 Karma

thefuzz4
Path Finder

Yeah I guess I'm trying to figure out how to match say the hostname to the service now ticket description. Thats where I'm hung up with this I was hoping that someone else has used servicenow and splunk events together. Sorry for the delayed response, was working on other items on Fri and then ya know weekend :). Thank you Jeremiah for your help with this.

So like

From splunk event
host=host-prod

From servicenow event in splunk
hort_description="host-prod"

Let me know if that makes sense or what other information you'll need. Thanks.

0 Karma
Get Updates on the Splunk Community!

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...

IM Landing Page Filter - Now Available

We’ve added the capability for you to filter across the summary details on the main Infrastructure Monitoring ...

Dynamic Links from Alerts to IM Navigators - New in Observability Cloud

Splunk continues to improve the troubleshooting experience in Observability Cloud with this latest enhancement ...