Hi Team,
We are having an issue where we are not getting data from ServiceNow into Splunk. How do I go about it? Can you please help me with the troubleshooting steps?
The first place to look is in in your _internal index at the ta_snow sourcetype.
index=_internal sourcetype=ta_snow
That will have the logs from the scripts that are collecting data from Service Now. You should be able to see if Splunk is able to connect or not, collect data, and also any errors that might be occurring. At this point you can follow up on the errors in the log. If you don't see those logs at all in Splunk, then take a look where you have deployed the Service Now TA to make sure that you are correctly forwarding data from that system and that the TA is enabled.