Install and configure the ServiceNow application for the Splunk Enterprise Event Ingestion integration
Install and configure Splunk Enterprise security- Event Ingestion integration from the ServiceNow Store on your ServiceNow AI Platform instance.
Before you begin
Role required: sn_si.ingestion_profile_admin
Note: Users with the sn_si.admin role can perform all operations available to a profile admin, as the sn_si.admin role inherits the required permissions by default.
Procedure
If you have not installed the Splunk Enterprise Event Ingestion application from the ServiceNow Store for the integration, see Install a Security Operations integration and follow the steps to install it.
Navigate to All > Integrations > Integrations Configurations
Search for Splunk Enterprise security- Event Ingestion tile, and select Configure.
On the form, fill in the fields.
| Field | Description |
|---|---|
| Name | Name of the Splunk Enterprise console or Splunk Cloud instance used for the integration.Spaces are supported for names, but parentheses are not supported. For example, enter `HQ-USA`, or `HQ USA`. |
| Splunk API Base URL | URL for your Splunk Enterprise console or Splunk Cloud instance. |
| Basic Authentication | Default is disabled.If you are using API Account User Name and API Password for configuration, enable the check box. |
| API Account User Name | User name that you created for your individual user account on the Splunk Enterprise console. |
| API Password | Password that you created for your individual user account on the Splunk Enterprise console. |
| Token Based (available from version 12.0.0) | Token based authentication that you created for your API user account on the Splunk Enterprise console. |
| Token | Token that you created for your API user account on the Splunk Enterprise console. |
| MID Server | Specific MID Server that is set up in your environment. Only MID Servers that are active and validated are available from this choice list. |
| On Premises Deployment | Default is disabled. If you are using the cloud-based version of Splunk Enterprise, verify that the check box is cleared. If this option is enabled, the MID Server choice list is displayed. If you are using an on-premises version of Splunk Enterprise, follow these steps to select a MID Server.
A choice list is displayed. Default is Any.
|
Each Splunk Enterprise alert that you ingest from your Splunk Enterprise console requires a unique event profile in your ServiceNow AI Platform® instance. However, the source that you configure on the Event Ingestions Configuration form can be reused for multiple ServiceNow AI Platform® profiles as long as each profile ingests unique Splunk triggered alerts.
Select Submit.
The configured integration tile displays.
If an error message is displayed after you click Submit, enter your information again and click Submit.
What to do next
You have successfully installed and configured the application. The next step is to create an event profile.
- Configure Splunk Enterprise Event Ingestion settings
Use the Splunk Enterprise Event Ingestion settings to modify the preset configurations and their values as per your requirements.
Parent Topic:Splunk Enterprise Event Ingestion integration for Security Operations by ServiceNow
Previous topic:Set up your ServiceNow AI Platform instance for the Splunk Enterprise Event Ingestion integration
Next topic:Configure Splunk Enterprise Event Ingestion settings