The CreatorCon Call for Content is officially open! Get started here.

Send ServiceNow application log data to Splunk

brdr
Mega Contributor

Hello, we have several instances of ServiceNow at our company. We been asked by CIS to ingest ServiceNow application log data into Splunk for ServiceNow instances hosted centrally (SaaS). Does ServiceNow provide an API that sends their application/system logs to our Splunk instance running on AWS? Can we configure servicenow to send log events to an endpoint?

Thank you.

5 REPLIES 5

MGanon
Tera Guru

The integration is handled within Splunk. These are the notes that I took from the Security Fundamentals course:

  • Advanced Log File Analysis
  • Splunk Incident Enrichment integration
    • Searches logs
    • Adds relevant sighting information to Security Incidents
  • Built-in Search Processing Analysis
  • Add-On for Splunk from Splunkbase
  • No ServiceNow plugin to activate; configured within Splunk
  • Seamlessly create Security Incidents or events from Splunk events, alerts, and logs
  • Integration includes
    • Splunk Add-On
    • Manual Search Commands – create events and alerts from within Splunk
    • Custom event actions

Configure the connection in ServiceNow by navigating from Security Operations > Integration Configuration.

The Splunk - Event Ingestion is described here as:
"Splunk Enterprise integration is supported via a Splunk provided REST API that can consume logging alerts and notable events to create security incidents. Enable the configuration to allow the Security Incident Response application to pull log event data from Splunk"

The "Splunk Search Integration for Security Operations" integration has a ServiceNow Store app: https://store.servicenow.com/sn_appstore_store.do#!/store/application/9c6741f10b12220069d7ea7885673a52/7.0.2

Hope this helps. If not, you will probably have better response in the Security Operations forum: https://community.servicenow.com/community?id=community_forum&sys_id=be299a2ddbd897c068c1fb651f9619bb

Brian Lancaster
Tera Sage

Did you find an answer to this?  I'm looking for the same thing.  A way to get ServiceNow logs into splunk.

Anyone figure this out?

Kind of an old post, but check this out on syslog probes