Send ServiceNow application log data to Splunk
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎05-19-2020 08:23 AM
Hello, we have several instances of ServiceNow at our company. We been asked by CIS to ingest ServiceNow application log data into Splunk for ServiceNow instances hosted centrally (SaaS). Does ServiceNow provide an API that sends their application/system logs to our Splunk instance running on AWS? Can we configure servicenow to send log events to an endpoint?
Thank you.
- 5,971 Views
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎05-19-2020 08:07 PM
The integration is handled within Splunk. These are the notes that I took from the Security Fundamentals course:
- Advanced Log File Analysis
- Splunk Incident Enrichment integration
- Searches logs
- Adds relevant sighting information to Security Incidents
- Built-in Search Processing Analysis
- Add-On for Splunk from Splunkbase
- No ServiceNow plugin to activate; configured within Splunk
- Seamlessly create Security Incidents or events from Splunk events, alerts, and logs
- Integration includes
- Splunk Add-On
- Manual Search Commands – create events and alerts from within Splunk
- Custom event actions
Configure the connection in ServiceNow by navigating from Security Operations > Integration Configuration.
The Splunk - Event Ingestion is described here as:
"Splunk Enterprise integration is supported via a Splunk provided REST API that can consume logging alerts and notable events to create security incidents. Enable the configuration to allow the Security Incident Response application to pull log event data from Splunk"
The "Splunk Search Integration for Security Operations" integration has a ServiceNow Store app: https://store.servicenow.com/sn_appstore_store.do#!/store/application/9c6741f10b12220069d7ea7885673a52/7.0.2
Hope this helps. If not, you will probably have better response in the Security Operations forum: https://community.servicenow.com/community?id=community_forum&sys_id=be299a2ddbd897c068c1fb651f9619bb

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎08-20-2020 12:00 PM
Did you find an answer to this? I'm looking for the same thing. A way to get ServiceNow logs into splunk.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎09-27-2021 02:08 PM
Anyone figure this out?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎09-20-2023 01:50 PM
Kind of an old post, but check this out on syslog probes