Set up ServiceNow Event Ingestion Integration add-on
Install and set up the ServiceNow Event Ingestion Integration add-on in your Splunk enterprise console or Splunk Cloud instance.
Avant de commencer
Create a Manual event forwarding profile to forward alerts on-demand from your splunk console to create a Security Incident Response (SIR) on the ServiceNow instance. For more information, see Create and name an event profile and implement same for Splunk V2.
This add-on setup is necessary to enable manual event forwarding for the Splunk profile. Up-to two configurations can be created for a particular add-on. (Splunk Primary and Splunk Secondary)
Verify that you have installed the application for this integration from the ServiceNow Store before installing the add-on plugin from splunkbase that is required for manual event ingestion. If you have not installed the application for the integration from the ServiceNow Store, see Install and configure the ServiceNow application for the Splunk Enterprise Event Ingestion integration and follow the instructions to install it.
Role required: ServiceNow AI Platform administrator (admin)
Pourquoi et quand exécuter cette tâche
If you want to export events manually and on-demand from your Splunk console for the integration, download, and set up the ServiceNow Event Ingestion Integration add-on from Splunkbase in your Splunk console.
This ServiceNow extension add-on is required so that security incidents can be created from manually exported events in your ServiceNow AI Platform instance. This ServiceNow Event Ingestion Integration add-on is available on splunkbase.
For manual event forwarding, you can identify up to two different ServiceNow AI Platform endpoints (instances) in your Splunk Enterprise console. You forward the events to the endpoint or endpoints manually to create security incidents. For example, you can specify both a staging (development) instance and a production instance. By specifying separate instances and naming primary and secondary workflows for each instance, you can choose where you want to forward different events.
Procédure
-
If you have not already installed the ServiceNow Event Ingestion Integration add-on, follow these steps to install and configure it.
-
To set up the Addon, follow these steps.