All Apps and Add-ons

Splunk to Servicenow integration via Email

swatghare
Path Finder

Hello
We are trying to integrate Splunk (with Enterprise Security) with ServiceNow and we cannot use direct integration due to below points:
1. ServiceNow is using Jakarta version which we do not see currently being supported by Splunk
2. ServiceNow team is not ready to install Splunk plugin in their environment due to some techinical issues

So we are trying to achieve the integration by sending ES Splunk Alert as Email and then Email inputs will be mapped with ServiceNow.
We need help/information if we can get same fields / inputs from ES Correlation search into an Email so as to ticket in servicenow.

If someone have tried earlier then please help me to get this integration working by getting same fields and inputs as we received through direct integration.

Regards
Sushant

Tags (1)
0 Karma

nickhills
Ultra Champion

Not that it helps you directly, but Splunk_TA_snow 3.0 which supports Jakarta was released a few days ago.
You could try a bit more arm-twisting?

If my comment helps, please give it a thumbs up!
0 Karma

koshyk
Super Champion

are you using servicenow saas? They should be able to easily upgrade. Also there is Service Now SecOps app to do it too: https://docs.servicenow.com/bundle/istanbul-security-management/page/product/splunk-integration/conc...

0 Karma

swatghare
Path Finder

They cannot upgrade, as it is shared between many customer (shared SNOW) , so no plug in installation is possible. This is the reason we are trying Email Integration , but normal email integration have limited data it do not populate the data as done by pre-built apps in Splunk/SNOW.

Do anyone have any script which can convert the ES Correlation Search into XML and feed into ServiceNow

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...