Getting Data In

How to integrate Splunk with servicenow without duplicate table records?

abhishekroy168
Path Finder

Hi all,
I have integrated splunk with servicenow to get all tables from servicenow.
Recently I observed that whenever I am updating a table in servicenow i get 2 copies of it in Splunk .
I mean whenever there is an update for a table in servicenow for N number of times I am getting N numbers of a table in Splunk even though there is only 1 table in servicenow.
Please do help if any of you have any leads regarding this:)

0 Karma

jslay_splunk
Splunk Employee
Splunk Employee

This is expected behavior. You get a copy of every "state" of the record in splunk. You should just look at the latest record to get the most updated information. You can do this with |dedup sys_id

0 Karma

abhishekroy168
Path Finder

thanks @jslay for the answer.
I have done the same thing using distinct_count.
But I need something OOTB which can do it during the process of data plucking from servicenow.
Because using dedup for every query will make it fuzzy:)

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...