---
sourceDocument: Zurich ServiceNow AI Platform Capabilities
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/servicenow-platform

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich ServiceNow AI Platform Capabilities

ft:clusterId :

    - platcap

bundleId :

    - platcap

workflow :

    - Platform


---

# Install the add-on

# Install the add-on for the Service Graph Connector for Splunk {#ariaid-title1}

* Release version: Zurich
* 
* Updated August 8, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Install the Splunk add-on developed by ServiceNow® engineering from splunkbase to search for Windows and Linux Assets.

## Before you begin

Role required: admin or security_admin

## Procedure

1. Navigate to splunkbase ([splunkbase](https://splunkbase.splunk.com/app/7355)) and log in.
2. In your Splunk console, select AppsFInd More Apps.
3. Locate the ServiceNow Add-on for Windows and Linux Assets app and select Install.  
   Note:  
   You can upgrade from within the app.
4. Follow the prompts.
5. **Optional:** Navigate to SettingsSearches, reports and alerts to view when searches are scheduled.  
   Note:  
   You can change the schedules, but since the schedules run in a specific order and require successful completion before the next search in the list is initiated, you might prefer to leave the settings in their
   defaults.

   After all the searches are completed, the data is grouped from each search into a few coalesced key-value parings (kvstores) for import into your instance: asset details, asset process details, asset service
   details, and asset software details.
6. Select App: Search and Reporting (search)ServiceNow Add-on for Windows and Linux Assets.  
   By default, search data is stored in the following key definitions:
   * Asset_index_macro: Index="internal"
   * Asset_linex_Index_macro: index="main"
   * Asset_windows_index="main"
   {#spc-install-splunk-add-on__ul_btk_2hx_2dc}

   If you are storing the search data for Linux and Windows in custom indexes, you must update your search macros.
7. To update your search macros, navigate to SettingsAdvanced searchSearch macrosSearch \& Reporting (Search)ServiceNow Add-on for Windows and Linux Assets ServiceNow_TA_windows_linux_assets
8. On the Search macros page, update the index as required in the Definition column.
9. **Optional:** Adjust workloads to specify resources for search, indexing, and other workloads.
   1. In Splunk Web, select SettingsWorkload ManagementWorkload Rules.
   2. In the Status column, select the toggle to activate or deactivate individual workload rules.

   {#spc-install-splunk-add-on__substeps_jq1_1jx_2dc}  
   See [Service Graph Connector for Splunk add-on](https://www.servicenow.com/docs/vjXQdB2VxmfabQMj~N4ZQA "Import more detailed asset data with the Service Graph Connector for Splunk with an add-on developed by ServiceNow engineering. The add-on permits you to import data about your Windows and Linux assets.") for more information about target workloads and supported deployments.

*[\>]: and then


