Schedule and retrieve alerts for the Splunk Enterprise Event Ingestion integration
For automated alert ingestion profiles, this step is final step of the event profile configuration. During this step, you can verify the default settings for alert retrieval or modify the scheduling as needed. This step permits you to filter your alert retrieval based on a date range.
Before you begin
Role required: sn_si.ingestion_profile_admin
About this task
After you have completed all the steps in the progress bar for the profile configuration as shown in the following figure, you have completed the configuration for profiles for manual event forwarding. There is no scheduling available for events forwarded manually from your Splunk Enterprise console. For profiles for automated alert ingestion, you choose whether you want to ingest any historical alerts during the Scheduling step. You also choose how often you will poll for future alerts that match the alert profile configuration.
For automated alert ingestion profiles, before the profile is activated, you verify and modify the scheduling and alert retrieval. This step is the final step of the event profile configuration process for scheduled alert profiles.
Configure these polling intervals on a per-profile basis. The performance of the Splunk event ingestion integration is impacted by the different polling intervals. When scheduling, you may prefer to balance system load against incident urgency. A five-minute default value is set for any profile, but you may prefer to modify this setting based on the urgency of the incident and the anticipated load on your system.
In the Splunk Enterprise console, you set an alert to trigger that is based on increments or on a specific time. Use this setting to help you configure the scheduling in your ServiceNow AI Platform instance so the time increments in your Splunk Enterprise console synchronize with the scheduling that you set up in your ServiceNow AI Platform instance.