All Apps and Add-ons

Splunk to Servicenow integration via Email

swatghare
Path Finder

Hello
We are trying to integrate Splunk (with Enterprise Security) with ServiceNow and we cannot use direct integration due to below points:
1. ServiceNow is using Jakarta version which we do not see currently being supported by Splunk
2. ServiceNow team is not ready to install Splunk plugin in their environment due to some techinical issues

So we are trying to achieve the integration by sending ES Splunk Alert as Email and then Email inputs will be mapped with ServiceNow.
We need help/information if we can get same fields / inputs from ES Correlation search into an Email so as to ticket in servicenow.

If someone have tried earlier then please help me to get this integration working by getting same fields and inputs as we received through direct integration.

Regards
Sushant

Tags (1)
0 Karma

nickhills
Ultra Champion

Not that it helps you directly, but Splunk_TA_snow 3.0 which supports Jakarta was released a few days ago.
You could try a bit more arm-twisting?

If my comment helps, please give it a thumbs up!
0 Karma

koshyk
Super Champion

are you using servicenow saas? They should be able to easily upgrade. Also there is Service Now SecOps app to do it too: https://docs.servicenow.com/bundle/istanbul-security-management/page/product/splunk-integration/conc...

0 Karma

swatghare
Path Finder

They cannot upgrade, as it is shared between many customer (shared SNOW) , so no plug in installation is possible. This is the reason we are trying Email Integration , but normal email integration have limited data it do not populate the data as done by pre-built apps in Splunk/SNOW.

Do anyone have any script which can convert the ES Correlation Search into XML and feed into ServiceNow

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...