---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# ServiceNow Security Operations add-on for Splunk overview

# ServiceNow
Security Operations add-on for Splunk
overview {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The ServiceNow
Security Operations add-on for Splunk allows a Splunk software
administrator to collect data and create incidents and events in the ServiceNow AI Platform.  
The add-on is installed from [Splunkbase.](https://splunkbase.splunk.com/)  
Important:  
Splunk is also supported for Managed Service Provider (MSP) environment.
**Related tasks**   

* [Setup Splunk environment](https://servicenow-prod.fluidtopics.net/0gxbXDSKMOcLQkOJNBwEUQ "ServiceNow Security Operations Integration enables seamless integration between Splunk and ServiceNow Security Operations. To set up or change the ServiceNow instance where new security incidents and security events are created, use the setup action in the application list.")
* [Configure Application Registry on the ServiceNow instance](https://servicenow-prod.fluidtopics.net/3nbvNEQ1CWNpuIeT2_nrvg "Register the application with the instance to use OAuth authorization.")
* [Using ServiceNow Security Operations Integration add-on](https://servicenow-prod.fluidtopics.net/~O6tF_eXz3w7NZX6zHuvpw "Create security events and incidents directly from Splunk alerts after setting up ServiceNow Security Operations Integration add-on.")

