---
sourceDocument: Australia IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/it-operations-management

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Add Splunk Enterprise chart data

# Add Splunk Enterprise data to Service Observability dashboard templates {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Add Splunk Enterprise data to charts on Service Observability dashboard templates when you want to view those metrics in context of Service Observability.

## Warum und wann dieser Vorgang ausgeführt wird

You can add metrics that are stored in Splunk Enterprise to your Service Observability dashboards. These charts display with data from the query you add to the chart.  
Hinweis:  
The results from these queries are not automatically scoped to the selected service.

## Vorbereitungen

You need a connection to your Splunk Enterpise instance. See [Connect a Service Observability data source](https://servicenow-prod.fluidtopics.net/nLQDmN9XD6_07ekdPuQduw "Connect Service Observability to an external observability system. Service Observability displays metrics in the Service Operations Workspace (SOW) from that observability instance.") for more information.

Role required: sn_sow_svcobs.admin

## Prozedur

1. Navigate to WorkspacesService Operations Workspace and then navigate to a service record.  
   You can access a service record from these pages in the SOW:
   * Services list: Choose a service from the list.
   * Service dashboard: Choose a service in the dashboard and select Service Details.
   * List: Navigate to Application ServicesServices and select a service.
   * Express list alert: Select a service from the Impacted services column.
   {#add-splunk-enterprise-data__ul_k1f_vt1_zdc}  
   The Service Details page opens and the Overview tab is displayed.
   If charts are displaying error messages, see [Chart error states](https://servicenow-prod.fluidtopics.net/XTiVe7nf04w6yQys7031uw "Understand the different error states that the charts in Service Observability might display and how to fix them.").
2. Open the template in editing mode.
   * If you're editing a certified template, select Duplicate.
   * If you're editing a custom template, select Edit.

   {#add-splunk-enterprise-data__choices_ljc_bmj_23c}  
   Hinweis:  
   Duplicating a certified template keeps you from overwriting it and also lets you reinstall it.
   The new dashboard is titled with the words <kbd class="ph userinput">- Copy</kbd> appended. Use the pencil icon to change the dashboard name.
3. To do basic editing, such as rearranging, resizing, or deleting charts, follow the instructions for [Edit in-line Platform Analytics dashboard elements](https://www.servicenow.com/docs/access?context=edit-db-elements-in-ac&version=australia&pubname=australia-now-intelligence&ft:locale=en-US).
4. To add a new chart with MetricBase data, follow these steps:
   1. In Edit mode, select Add new element and choose Data visualization, select New Visualization, and then select Line.
   2. In the Data sources section of the Configuration panel, select Add data source.
   3. In the Add data source page, navigate to Service ObservabilitySplunk Enterprise Metrics, paste in a query from an existing Splunk chart, and then choose Add this source.  
      The data is added to the dashboard.
   4. Use the controls in the Data section of the Configuration panel to select the metric and configure the query.
   {#add-splunk-enterprise-data__substeps_rnj_typ_s2c}
5. When done customizing, select Save and then Exit editing mode.
6. To return the template to the default (Certified) version, use the More actions menu to select Return to certified.
{#add-splunk-enterprise-data__steps_kjc_bmj_23c}

