All Apps and Add-ons

Is there a way that I can update my Splunk lookup table through Service Now or calling the REST API ?

Gunjan92
Engager

I want my lookup table consisting of blacklisted IPs to be updated by ServiceNow automatically through alert rather than entering it in the EDL manually. Is there a way ?

0 Karma

dkeck
Influencer
0 Karma

dkeck
Influencer

Did this work for you ?

if it helped please accept the question 🙂

0 Karma

Gunjan92
Engager

I am trying to run the query for creating a lookup table but all I get is results not found.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...