Using ServiceNow Security Operations Integration add-on
Create security events and incidents directly from Splunk alerts after setting up ServiceNow Security Operations Integration add-on.
Before you begin
Role required: sn_si.integration_user, sn_si.analyst
Procedure
Log in to Splunk Enterprise.
Navigate to Apps > Search & Reporting.
Enter a keyword in the New Search field.
A list of events with the keyword show up.
Expand any of the events using (>) icon.
Select Event Actions.
Create ServiceNow Security Event: Events are stored in the em_event table.
Note:
Install Event Management plugin to access the em_event table.
Create ServiceNow Security Incident: Incidents are stored in the sn_si_incident table.
Note: The mapping is pre defined as we don't have a profile for this add-on.
Image omitted: splunk-event-actions.png
Event actions in Splunk enterprise
Event actions in Splunk enterprise