Splunk ES Integration for Security Operations release notes
Summarize
Summarized using AI
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.
Summary of Splunk ES Integration for Security Operations release notes
The Splunk ES Integration for Security Operations enables Security Operations Center (SOC) analysts to automatically create Security Incident Response (SIR) incidents in the ServiceNow AI Platform when specific Splunk ES Notable Events occur. This integration also allows manual forwarding of selected events from the Splunk ES console. It supports automation of incident response workflows and remediation activities within ServiceNow.
Show less
Key Features and Enhancements
- Automated Incident Creation: Generates SIR incidents automatically from configured Splunk ES notable events to streamline SOC workflows.
- Manual Event Forwarding: Allows analysts to forward events on-demand from the Splunk ES console.
- Bidirectional Synchronization: Supports updates and closure synchronization between Splunk ES and ServiceNow incidents, including work notes and comments.
- Ingestion Profile Management: Users with the "snsi.ingestionprofileadmin" role can manage ingestion profiles for Splunk ES integration.
- Enhanced Security Controls: Dictionary-level fields upgraded to Strict Read-Only to prevent unauthorized changes.
- Improved Error Handling: Graceful handling of missing CMDB Configuration Items by marking them as Unmatched CIs.
- Support for Encrypted Fields: Added KMF support for mapping encrypted fields such as secure notes.
- Aggregation and Correlation Enhancements: New correlation rules are periodically imported; aggregation of Security Incidents based on "State" field enabled; fixes for aggregation logic in domain-separated environments and with logical operators.
- Performance Optimizations: Resolved memory contention issues causing node restarts in Splunk ES processes responsible for sending events to SIR.
- Bug Fixes: Numerous fixes including XML parsing errors blocking incident creation, field translation editing issues, token restoration bugs, stale record cleanups, and improved ingestion of updated notable events supporting Splunk ES version 8.0.x and later.
Practical Benefits for ServiceNow Customers
- Streamlines SOC incident management by integrating Splunk ES notable events directly into ServiceNow’s Security Incident Response workflows.
- Improves accuracy and reliability of event ingestion and incident correlation, reducing manual overhead and error rates.
- Enhances security and data integrity with strict read-only enforcement and encrypted field support.
- Enables flexible administration of ingestion profiles and synchronization of incident updates, boosting operational efficiency.
- Delivers improved performance and stability, minimizing disruptions in critical security monitoring processes.
Version history for the Splunk ES Integration for Security Operations application on the ServiceNow Store.
Important:
For details on system requirements and family compatibility, view the application
listing on the ServiceNow Store
website.
Version history
- Version 12.5.1 - June 2026
- Fixed:
- Refactored the UI macros and backend logic to correctly distinguish between sample types, removed unreachable dead code, and fixed correlation rule name lookup for multi-rule profiles.
- Access issues for Security Analyst while querying tables.
- Fixed:
- Version 12.5.0 - April 2026
-
- New:
- Handling missing CMDB CIs gracefully by attaching them as Unmatched CI.
- New correlation rules in Splunk ES automatically imported periodically based on system property.
- Fixed:
- Provided fix for ingestion of Updated Notables which supports Splunk ES version 8.0.x and later versions.
- Added KMF support for encrypted fields like secure notes mapping.
- New:
- Version 12.4.0 - December 2025
- New: Upgraded all dictionary-level read-only fields to Strict Read-Only to enhance security and prevent unauthorized changes.This update ensures the server consistently enforces read-only behaviour across all UIs, scripts, and integrations.
- Version 12.3.0 - November 2025
- Fixed:
- New splunk upgrade failing xml parsing and blocks SIR creation.
- Not able to edit existing Field translations.
- Fixed:
- Version 12.2.2 - October 2025
-
- Fixed:
- Token restoration bug in SplunkESEventIngestionQueryAbstract._buildInputValue corrupts literal values that look like $$ (e.g., $DOVERIE01$), leaving ____ placeholders and producing malformed input.
- SplunkES LockTable should have profile admin role instead of admin role.
- Aggregation bug in case of domain separation.
- Fixed:
- Version 12.2.1 - September 2025
- Fixed: Splunk ES update multiple is working in iterative mode. We have added fix to clean up the stale records in internal tables.
- Version 12.2.0 - August 2025
-
- New:
- Enabling users with "sn_si.ingestion_profile_admin" role to manage ingestion profiles on Splunk ES Integration.
- Update Field values for notable events in splunk ES.
- Ability to Aggregate SIR Security Incidents using the "State" field.
- Work Notes and Comments Synchronization for Splunk ES.
- Splunk ES Bidirectional Updates or Closure.
- Fixed:
- Aggregation not working in case of OR operator when the first field is empty.
- User is able to create multiple field translations for an attribute . Observed this in domain seperation case.
- New:
- Version 12.1.10 - July 2025
-
- Fixed:
- Issue: The Splunk Enterprise Security (ES) process responsible for sending events to the Security Incident Response (SIR) job was causing memory contention on nodes, resulting in unexpected node restarts.
- Improvement: Performance optimizations were implemented in Splunk ES, effectively resolving the memory contention issue and preventing further node restarts.
- Fixed:
- Version 12.1.9 - June 2025
-
- Fixed:
- Bug: The Splunk ES process for sending events to the Security Incident Response (SIR) job was causing memory contention on nodes, leading to node restarts.
- Improvement: Performance improvements were implemented for Splunk ES, which resolved the memory contention issue on nodes.
- Fixed:
- Version 12.1.6 - May 2025
-
- Fixed:
- The following bugs as part of this release:
- Supports adding multiple affected users during Splunk Enterprise event ingestion for Security Operations.
- sys_scope issue on the Xanadu instance that prevented linking a created source to the profile using the sn_si.admin role.
- An issue where the Splunk ES Event Profiles were not updating the existing notables and only new notables were being ingested.
- An issue where updated notables were not ingested if the correlation rule name contained a trailing space.
- When there is an issue in data for any record in the Splunk raw data table, event import was failing for remaining entries, these remaining entries are now executed as expected.
- The following bugs as part of this release:
- Fixed:
- Version 12.1.1 - November 2024
- The Splunk ES Event Ingestion integration for Security Operations allows security operations center (SOC) analysts to generate ServiceNow AI Platform Security Incident Response (SIR) incidents automatically when certain configured Splunk ES Notable Events are triggered. Analysts can also manually forward selected events on-demand from the Splunk ES console. Analysts respond to the security incidents that are created with workflows in the ServiceNow AI Platform that automate incident response activities and remediation.