Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

TISC add-on for Splunk overview

Configure the Threat Intelligence Security Center (TISC) integration with Splunk to import threat intelligence data, set up indicator collections, and analyze search matches using dashboards.

  • TISC integration with Splunk
    The integration between the Threat Intelligence Security Center (TISC) and Splunk lets you filter and pull relevant threat intelligence observables data into Splunk.In Splunk, you can use this data to generate security alerts.
  • Create users in TISC instance
    Users can be created in the ServiceNow TISC instance with any valid user role [sn_sec_tisc.api_obs_read_access].
  • Configure TISC add-on in Splunk
    Configure the TISC add-on in Splunk to connect your account, define data inputs, and pull observable records into the KV store for search and analysis.
  • Data storage in Splunk
    Configure and retrieve Key-Value store lookups used by TISC during its integration with Splunk.
  • Troubleshoot the TISC add-on in Splunk
    Enable debug logging on the add-on, view the resulting log entries in Splunk, and check input execution status from the Input Metadata Lookup KV store.

Parent Topic:TISC Security Tools integrations