Get started with the Splunk Search integration for Security Operations

  • Freigeben Version: Australia
  • Aktualisiert 12. März 2026
  • 1 Minute Lesedauer
  • Splunk software searches, monitors, and analyzes machine-generated big data and integrates easily with Security Operations. Before you can use the Splunk - Incident Enrichment integration, you must download it from the ServiceNow Store and add the appropriate API Base URL and login credentials.

    Vorbereitungen

    Role required: sn_si.admin

    Prozedur

    1. Download the integration from the ServiceNow Store.
    2. When the installation is complete, access Splunk and obtain the API Key and API ID under your profile.
    3. In your instance, navigate to Security Operations > Integration Configuration.
      The available security integrations appear as a series of cards.
    4. In the Splunk - Incident Enrichment card, click New.
      Splunk - Incident Enrichment Configuration
    5. Fill in the fields, as needed.
      Field Description
      Name The name of this configuration.
      Splunk API Base URL The base URL you acquired from the Splunk site.
      Link URL [Optional] The Link URL that links to the Splunk web interface, when available.
      Username Your Splunk username.
      Password Your Splunk password.
      Max Rows The maximum number of rows you want to search.
      Earliest Result (days) The earliest results you want to see in number of days.
      Include raw data samples in search results Select this to include samples of raw data in your sightings search results. The amount of data returned depends on your setting in the number of rows of raw data property in Security Incident Response properties.
      MID Server Select Any to use any active MID Server, or select a specific MID Server name.
      Hinweis:
      Configuring this integration activates workflows. To manage the workflows, navigate to the Workflow Editor.
    6. Click Submit.
      The integration configuration card displays.
    7. When viewing the new configuration card, you can click Configure or Delete to change or delete the configuration, respectively.
    8. To return to the original list of integration configuration cards, select No from the Show Configurations drop-down list.