Using ServiceNow Event Ingestion Integration add-on
Map alerts from Splunk console to create a Security Incident Response (SIR) on the ServiceNow instance.
Before you begin
Role required: sn_sec_splunk_v2.api_account_access
Procedure
Log in to Splunk Enterprise.
Navigate to Apps > Search & Reporting.
Select Alerts.
A list of alerts generated in the Splunk console on the basis of correlation rule configured previously show up.
Select any Configured Alert from the list.
Trigger History of the configured alert show up.
Select View Results against the alert.
Expand any of the alerts using (>) icon.
From the drop down, select the Workflow action label configured while setting up the add-on.
For more information on Workflow action label, see Set up ServiceNow Event Ingestion Integration add-on
Alerts will go in Splunk Import table followed by Splunk Event to Tasks table.
Result
A Security Incident Response (SIR) record is created on the ServiceNow instance as per the mapping specified in the Manual event forwarding profile. For instructions on how to set up a Manual event forwarding profile, see Create and name an event profile
Parent Topic:Integration architecture and external systems connection