---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create a multi-record, custom field Splunk alert

# Create a multi-record, custom field Splunk alert {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

To create a multiple record Splunk alert with custom fields, you must build a search
that is designed to match the ServiceNow columns you want to populate.

## Before you begin

Role required: sn_si.admin

## Procedure

1. Navigate to Search.
2. In the Search box, create a search that generates your record data.  
   See the [examples](https://servicenow-prod.fluidtopics.net/bwDbqJn4rJengdMFXskKTQ "When you are creating multiple record Splunk alerts with custom fields, you need to define search criteria for generating alert data. Examples of search criteria for security incidents and security events are shown.") for recommended search criteria.
3. Click Save As and select Alert.
4. Set the name, permissions, and schedule, as needed.
5. Click Add Actions.
6. Make one of the following selections.  
   * To create one event per result from your search, select Create Multiple ServiceNow Security Events.
   * To create one incident per result from your search, select Create Multiple ServiceNow Security Incidents.
   {#create-multi-record-alert__ul_tyw_wrp_mx}
7. Set any defaults, as needed.  
   If the field in the search result is blank or not present, the defaults are used. If there is a value in the result, the defaults are overwritten.

