Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Install and configure the ServiceNow application for the Splunk Enterprise Event Ingestion integration

Install and configure Splunk Enterprise security- Event Ingestion integration from the ServiceNow Store on your ServiceNow AI Platform instance.

Before you begin

Role required: sn_si.ingestion_profile_admin

Note: Users with the sn_si.admin role can perform all operations available to a profile admin, as the sn_si.admin role inherits the required permissions by default.

Procedure

  1. If you have not installed the Splunk Enterprise Event Ingestion application from the ServiceNow Store for the integration, see Install a Security Operations integration and follow the steps to install it.

  2. Navigate to All > Integrations > Integrations Configurations

  3. Search for Splunk Enterprise security- Event Ingestion tile, and select Configure.

  4. On the form, fill in the fields.

FieldDescription
NameName of the Splunk Enterprise console or Splunk Cloud instance used for the integration.Spaces are supported for names, but parentheses are not supported. For example, enter `HQ-USA`, or `HQ USA`.
Splunk API Base URLURL for your Splunk Enterprise console or Splunk Cloud instance.
Basic AuthenticationDefault is disabled.If you are using API Account User Name and API Password for configuration, enable the check box.
API Account User NameUser name that you created for your individual user account on the Splunk Enterprise console.
API PasswordPassword that you created for your individual user account on the Splunk Enterprise console.
Token Based (available from version 12.0.0)Token based authentication that you created for your API user account on the Splunk Enterprise console.
TokenToken that you created for your API user account on the Splunk Enterprise console.
MID ServerSpecific MID Server that is set up in your environment. Only MID Servers that are active and validated are available from this choice list.
On Premises Deployment

Default is disabled. If you are using the cloud-based version of Splunk Enterprise, verify that the check box is cleared.

If this option is enabled, the MID Server choice list is displayed. If you are using an on-premises version of Splunk Enterprise, follow these steps to select a MID Server.

  1. Select the check box.

A choice list is displayed. Default is Any.

  1. Select Any only if this MID server is configured for the Splunk Enterprise Event Ingestion integration.
  2. From the choice list, select the ServiceNow AI Platform® MID server that you configured in your instance for this specific integration.
Each Splunk Enterprise alert that you ingest from your Splunk Enterprise console requires a unique event profile in your ServiceNow AI Platform® instance. However, the source that you configure on the Event Ingestions Configuration form can be reused for multiple ServiceNow AI Platform® profiles as long as each profile ingests unique Splunk triggered alerts.
  1. Select Submit.

    The configured integration tile displays.

If an error message is displayed after you click Submit, enter your information again and click Submit.

What to do next

You have successfully installed and configured the application. The next step is to create an event profile.

Parent Topic:Splunk Enterprise Event Ingestion integration for Security Operations by ServiceNow

Previous topic:Set up your ServiceNow AI Platform instance for the Splunk Enterprise Event Ingestion integration

Next topic:Configure Splunk Enterprise Event Ingestion settings