Set up your Splunk environment for manual event ingestion for the Splunk Enterprise event ingestion integration
If you want to export events manually and on-demand from your Splunk Enterprise console for this integration, install and set up the ServiceNow Security Operations Event Ingestion Addon for Splunk Enterprise application in your Splunk enterprise console or Splunk Cloud instance.
Before you begin
Verify that you have installed the application for this integration from the ServiceNow Store prior to installing the addon plugin from splunkbase that is required for manual event ingestion. If you have not installed the application for the integration from the ServiceNow Store, see Install and configure the ServiceNow application for the Splunk Enterprise Event Ingestion integration and follow the instructions to install it.
Role required: ServiceNow AI Platform administrator (admin)
About this task
Installing and setting up the ServiceNow Security Operations Event Ingestion Addon is optional.
If you want to export events manually and on-demand from your Splunk Enterprise console for the integration, download, install, and set up the ServiceNow Security Operations Event Ingestion Addon for Splunk Enterprise from splunkbase in your Splunk Enterprise console.
This ServiceNow extension addon is required so that security incidents can be created from manually exported events in your ServiceNow AI Platform instance. This ServiceNow Security Operations Event Ingestion Addon for Splunk Enterprise application is available on splunkbase.
For manual event forwarding, you can identify up to two different ServiceNow AI Platform endpoints (instances) in your Splunk Enterprise console. You forward the events to the endpoint or endpoints manually to create security incidents. For example, you can specify both a staging (development) instance and a production instance. By specifying separate instances and naming primary and secondary workflows for each instance, you can choose where you want to forward different events.
Procedure
What to do next
If you have not already save searches in your Splunk Enterprise console, the next step is to save searches as alerts in your Splunk Enterprise console.