Save searches in your Splunk Enterprise console for the Splunk Enterprise Event Ingestion integration
The following steps for saving searches in your Splunk Enterprise console are provided for a user with the Splunk Enterprise administrator role.
Before you begin
If you already have existing saved searches and triggered alerts in your Splunk Enterprise console, you are not required to modify these searches for this integration.
The integration of the ServiceNow AI Platform® Security Operations product with the Splunk event notification service pulls event and alert information from Splunk.
Prior to ingesting alerts into your Security Operations environment, configure searches in your Splunk Enterprise console so that you automatically pull the relevant security events in Splunk Enterprise that you want to save as alerts.
If you do not have saved searches and triggered alerts established for notification when important security events occur in your Splunk Enterprise console, follow these steps to save searches.
Role required: Splunk Enterprise administrator
Procedure
What to do next
You have successfully completed the required setup for the integration in your Splunk Enterprise console. If you have not already installed the application for the integration from the ServiceNow Store, the next step is to install the application for the integration and configure it.