---
sourceDocument: Yokohama Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/security-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure

# Install and configure the ServiceNow application for the Splunk Enterprise Event Ingestion integration {#ariaid-title1}

* Release version: Yokohama
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Before you run the integration on your ServiceNow AI Platform® instance,
complete these installation and configuration steps so the application properly integrates
with the Security Incident Response and Security Operations products on your
ServiceNow AI Platform® instance.

## Before you begin

Role required: sn_si.ingestion_profile_admin  
Note:  
Users with the sn_si.admin role can perform all operations available to a profile admin, as the sn_si.admin role inherits the required permissions by default.

## Procedure

1. If you have not installed the Splunk Enterprise Event Ingestion application from the ServiceNow Store for the integration, see [Install a Security Operations integration](https://www.servicenow.com/docs/rmdDLn9I36POHMelYkGg0Q "All ServiceNow integrations are available on the ServiceNow Store. Core applications, such as Security Incident Response, are visible in the ServiceNow Products tab on the store. Integration add-ons are visible in the Certified Apps tab.") and follow the steps to install it.
2. After you have successfully installed the application, navigate to IntegrationsIntegrations Configurations and locate the Splunk Event Ingestions tile.
3. To configure the application, click New.  
4. Alternatively, if a Configure button is displayed on a tile, click it to edit an existing configuration.
5. In the Event Ingestions Configuration dialog that is displayed, fill in the fields.

   | Field | Description |
   | Name | Name of the Splunk Enterprise console or Splunk Cloud instance used for the integration. Spaces are supported for names, but parentheses are not supported. For example, enter <kbd class="ph userinput">HQ-USA</kbd>, or <kbd class="ph userinput">HQ USA</kbd>. |
   | Splunk API Base URL | URL for your Splunk Enterprise console or Splunk Cloud instance. |
   | Basic Authentication | Default is disabled. If you are using API Account User Name and API Password for configuration, enable the check box. |
   | API Account User Name | User name that you created for your individual user account on the Splunk Enterprise console. |
   | API Password | Password that you created for your individual user account on the Splunk Enterprise console. |
   | Token Based (available from version 12.0.0) | Token based authentication that you created for your API user account on the Splunk Enterprise console. |
   | Token | Token that you created for your API user account on the Splunk Enterprise console. |
   | MID Server | Specific MID Server that is set up in your environment. Only MID Servers that are active and validated are available from this choice list. |
   | On Premises Deployment | Default is disabled. If you are using the cloud-based version of Splunk Enterprise, verify that the check box is cleared. If this option is enabled, the MID Server choice list is displayed. If you are using an on-premises version of Splunk Enterprise, follow these steps to select a MID Server. 1. Select the check box.A choice list is displayed. Default is Any. 2. Select Any only if this MID server is configured for the Splunk Enterprise Event Ingestion integration. 3. From the choice list, select the ServiceNow AI Platform® MID server that you configured in your instance for this specific integration. {#splunk-event-ingest-install-and-configure__ol_ulq_r4g_5gb} |
   |-|-|

   {#splunk-event-ingest-install-and-configure__choicetable_rrp_bwk_kdb}  
   The following figure is an example of a completed form for a configuration of an
   on-premises version of Splunk Enterprise with a MID Server.

   Each Splunk Enterprise alert that you ingest from your Splunk Enterprise console requires a unique event profile in
   your ServiceNow AI Platform® instance. However, the source that you
   configure on the Event Ingestions Configuration form can be reused for multiple
   ServiceNow AI Platform® profiles as long as each profile ingests
   unique Splunk triggered alerts.
6. Click Submit.  
   After validation is successfully completed, the Security Integrations page is displayed with each of your configurations. On each valid configuration tile, Configure and Delete buttons are displayed as shown in the following figure.  
   Note:  
   You have to use either Basic Authentication or Token Based Authentication only. Enable one of the authentications and enter the corresponding authentication details. Enabling both will display an error.

   After it is successfully validated and submitted, each Event Ingestions Splunk server configuration is saved on the Security
   Integrations page as a tile. If your saved configuration tiles are not displayed
   on the Security Integrations page, on the top right corner of the page, from the
   Show Configurations choice list, click Yes.  
{#splunk-event-ingest-install-and-configure__steps_rvh_qsv_3fb} If an error message is displayed after you click Submit, enter
your information again and click Submit.

## What to do next

You have successfully installed and configured the application. The next step is to
create an event profile.
* **[Configure Splunk Enterprise Event Ingestion settings](https://www.servicenow.com/docs/tZqdEUKcad9bs3zWNnHwHA)**   
  Use the Splunk Enterprise Event Ingestion settings to modify the preset configurations and their values as per your requirements.

**Previous topic:** [Set up your ServiceNow AI Platform instance for the Splunk Enterprise Event Ingestion integration](https://www.servicenow.com/docs/WkaV0kL4r1MN6~kvSlIvvQ "The following section lists the setup tasks that you are required to complete in your ServiceNow AI Platform instance prior to installing the application from the ServiceNow Store.")  
**Next topic:** [Configure Splunk Enterprise Event Ingestion settings](https://www.servicenow.com/docs/tZqdEUKcad9bs3zWNnHwHA "Use the Splunk Enterprise Event Ingestion settings to modify the preset configurations and their values as per your requirements.")

*[\>]: and then


