Splunk to ServiceNow Integration (Incident need to be raised in the Incidents section)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-02-2023 02:26 AM - edited 03-02-2023 02:27 AM
Hello All,
I have installed the ServiceNow Security Operations addon in Splunk (https://splunkbase.splunk.com/app/3921) and validated the authentication also and then i have configured an alert with alert name, impact, urgency and every details. When the alert is getting fired in Splunk the incident is getting created in the Security Incident section in service now.. But i want to get the ticket created directly in the Incidents section. So how can I change the settings for that. Currently i am using the developer instance and Splunk On-prem.
Please help me with the solution.
Thanks in Advance
Mohan