Checklist for Splunk Enterprise Security Notable Event Ingestion integration
Use this checklist to guide you through all the tasks of the integration. The following checklist includes setup and installation tasks and examples of use cases that include expected results for the integration.
Before you begin
Roles required: sn_si.ingestion_profile_admin, admin, sn_si.admin, sn_si.analyst, Splunk Enterprise Security administrator
Note: Users with the sn_si.admin role can perform all operations available to a profile admin, as the sn_si.admin role inherits the required permissions by default.
About this task
Track your progress with the setup, installation, and configuration of the integration with the following table. Complete all the tasks for a step before moving on to the next step. Each row of the table lists tasks and identifies the roles that are required to perform the tasks. Numbered topics of the installation and configuration guide are also referenced.
Roles required for each task are listed with each step in the following table.
Procedure
Track your progress with the setup, installation, and configuration of the integration.
Complete all the tasks for a step before moving on to the next step.
Follow the steps in the table in the order that they are presented.
| 1. | As a user with the ServiceNow AI Platform admin role, set up your ServiceNow AI Platform instance.
|
| 2. | As a user with the ServiceNow AI Platform admin role, install and configure the Splunk Enterprise Security application from the ServiceNow Store. 1. Download and install the application on your ServiceNow AI Platform instance. 2. Configure the application and connect to your Splunk Enterprise Security console. For more information, see Install and configure Splunk Enterprise Security Notable Event Ingestion integration. |
| 3. | \(Optional\) If you intend to export events manually from your Splunk Enterprise Security console to your ServiceNow AI Platform instance, perform the following tasks: - As a Splunk Enterprise Security administrator, install, set up, and enable the ServiceNow Security Operations Event Ingestion Addon for Splunk Enterprise Security from splunkbase in your Splunk Enterprise Security console. - As a Splunk Enterprise Security administrator, if not already configured, save searches as notable events in your Splunk Enterprise Security console. |
| 4. | As a user with the ServiceNow AI Platform sn_si.ingestion_profile_admin role, create and name an event profile. Select the profile type from the choice list. Options are a scheduled alert profile that you use to ingest sample data, or, an event profile that you use to export attachment data manually from your Splunk Enterprise Security console.
|
| 5. | As a user with the ServiceNow AI Platform sn_si.ingestion_profile_admin role, map values ingested or attachment data that is exported from Splunk Enterprise Security to ServiceNow AI Platform security incidents.
|
| 6. |
|
| 7. | As a user with the ServiceNow AI Platform sn_si.ingestion_profile_admin role, schedule alert retrieval for a profile with a scheduled alert. For more information, see Schedule and retrieve notable events. |
You have successfully completed the setup steps and verified expected results for the integration.