---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Splunk integration setup

# Splunk integration setup {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

Setup procedures for the ServiceNow
Security Operations add-on for Splunk
include downloading the add-on file in Splunk, installing the add-on, and setting up the ServiceNow instance where security
incidents and events are created.

## Required role {#setup-splunk-integration__section_lwv_t3h_v1b}

Before performing Splunk integration setup procedures, be sure to define an integration user
with the sn_si.integration_user and sn_si.analyst roles on your ServiceNow instance.
Additionally, in order to perform imports, you need the import_transformer role to obtain read
and write permission to the security tables. The sn_si.integration_user role should be defined
with the import_transformer portion of the role.

