Event Ingestion
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12 hours ago
Hello Folks,
Can someone please guide me on how events are ingested into ServiceNow Event Management using a MID Server?
I have already configured the MID Server and added Event Management under the Supported Applications section. Apart from this, I would like to understand:
How exactly does the MID Server ingest or forward events into ServiceNow?
What additional configurations are required on the ServiceNow side (event sources, connectors, event rules, etc.)?
How does this integration typically work with a monitoring tool like SolarWinds?
I am trying to understand the end-to-end flow of event ingestion from SolarWinds → MID Server → ServiceNow Event Management.
Any guidance or references would be appreciated.
Thanks
- Labels:
-
Event Management
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
7 hours ago
Hi my Friend
Think of the MID Server as a secure messenger, not the brain.
It does not decide what an event is or what to do with it. Its only job is to receive or fetch events inside your network and pass them to ServiceNow.
How events actually get into ServiceNow
SolarWinds → MID Server → ServiceNow Event Management
SolarWinds detects an issue
A device goes down, threshold breached, service degraded, etc.
SolarWinds sends or exposes the event
Either pushes it (SNMP traps / API calls)
Or ServiceNow pulls it using a SolarWinds connector
MID Server
Listens for those events or runs the connector
Securely forwards the raw event data to ServiceNow
ServiceNow Event Management
Stores the event
Applies Event Rules
Creates or updates alerts
Handles correlation, CI mapping, and incident creation
What you need to configure in ServiceNow
How events are collected (SolarWinds connector or SNMP traps)
A connector or listener tied to the MID Server
Event Rules (this is where most issues usually are)
Important clarification
If SolarWinds is creating incidents directly, that’s not Event Management.
True Event Management means events → alerts → correlation → incidents.
Bottom line:
The MID Server is just the delivery truck.
ServiceNow Event Management decides what the event means and what happens next.
@csatish - Please mark Accepted Solution and Thumbs Up if you found Helpful!!
