---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Checklist

# Checklist for Splunk Enterprise Security Notable Event Ingestion integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Use this checklist to guide you through all the tasks of the integration. The
following checklist includes setup and installation tasks and examples of use cases that
include expected results for the integration.

## Before you begin

Roles required: sn_si.ingestion_profile_admin, admin, sn_si.admin, sn_si.analyst, Splunk Enterprise Security administrator  
Note:  
Users with the sn_si.admin role can perform all operations available to a profile admin, as the sn_si.admin role inherits the required permissions by default.

## About this task

Track your progress with the setup, installation, and configuration of the integration
with the following table. Complete all the tasks for a step before moving on to the next
step. Each row of the table lists tasks and identifies the roles that are required to
perform the tasks. Numbered topics of the installation and configuration guide are also
referenced.

Roles required for each task are listed with each step in the following table.

## Procedure

1. Track your progress with the setup, installation, and configuration of the integration.  
   Complete all the tasks for a step before moving on to the next step.
2. Follow the steps in the table in the order that they are presented.  
   {#splunk-event-ingest-checklist-security__table_f2c_xn4_sgb__entry__2}

   |   |   |
   |-|-|
   | 1. | As a user with the ServiceNow AI Platform admin role, set up your ServiceNow AI Platform instance. * Assign users with the sn_si.ingestion_profile_admin (or sn_si.admin) and sn_si.analyst roles as required. * Install and configure a MID Server if the Splunk server is deployed within your corporate network. * Verify that the ServiceNow Security Incident Response plugins are activated for your release of the ServiceNow AI Platform. * (Optional) If you want to forward events manually from your Splunk Enterprise Security console into your ServiceNow AI Platform instance, verify that you have assigned the (sn_sec_splunkes.api_account_access) role to a user with the Splunk Enterprise Security administrator permission. {#splunk-event-ingest-checklist-security__ul_q3c_wc2_ygb} For more information, see [Set up your ServiceNow AI Platform instance for the Splunk Enterprise Security integration](https://servicenow-prod.fluidtopics.net/xswGY~zzgHhsqLtA7ZEjdg "The following section lists the setup tasks that you are required to complete in your ServiceNow AI Platform instance prior to installing the application from the ServiceNow Store."). |
   | 2. | As a user with the ServiceNow AI Platform admin role, install and configure the Splunk Enterprise Security application from the ServiceNow Store. 1. Download and install the application on your ServiceNow AI Platform instance. 2. Configure the application and connect to your Splunk Enterprise Security console. {#splunk-event-ingest-checklist-security__ol_o1m_k44_sgb} For more information, see [Install and configure Splunk Enterprise Security Notable Event Ingestion integration](https://servicenow-prod.fluidtopics.net/d5Tt4_zNCEJfKUzmVV1Bcw "Install and configure Splunk Enterprise Security Notable Event Ingestion integration for Security Operations application from the ServiceNow Store on your ServiceNow AI Platform instance."). |
   | 3. | (Optional) If you intend to export events manually from your Splunk Enterprise Security console to your ServiceNow AI Platform instance, perform the following tasks: * As a Splunk Enterprise Security administrator, install, set up, and enable the ServiceNow Security Operations Event Ingestion Addon for Splunk Enterprise Security from splunkbase in your Splunk Enterprise Security console. * As a Splunk Enterprise Security administrator, if not already configured, save searches as notable events in your Splunk Enterprise Security console. {#splunk-event-ingest-checklist-security__ul_pc4_tpw_bhb} |
   | 4. | As a user with the ServiceNow AI Platform sn_si.ingestion_profile_admin role, create and name an event profile. Select the profile type from the choice list. Options are a scheduled alert profile that you use to ingest sample data, or, an event profile that you use to export attachment data manually from your Splunk Enterprise Security console. * For a scheduled alert, select an available alert. * For profile for manually exported data, create a new map or copy an existing map. {#splunk-event-ingest-checklist-security__ul_ds4_w32_ygb} For more information, see [Create and name an event profile for the Splunk Enterprise Security event ingestion integration](https://servicenow-prod.fluidtopics.net/v9spPHbKI2udP0VNrCxkhw "You create an event profile in your ServiceNow AI Platform instance and determine which Splunk notable events create security incidents."). |
   | 5. | As a user with the ServiceNow AI Platform sn_si.ingestion_profile_admin role, map values ingested or attachment data that is exported from Splunk Enterprise Security to ServiceNow AI Platform security incidents. 1. Fetch sample data for a scheduled alert. 2. (Optional) Export attachment data manually from Splunk Enterprise Security for an event. 3. Edit the default mapping configuration. 4. Optionally add filtering criteria, append an alert to an existing security incident, and use the script editor. {#splunk-event-ingest-checklist-security__ol_rdf_dp4_sgb} For more information, see [Explore Mapping](https://servicenow-prod.fluidtopics.net/~jVPeN6fYvIBBDbCEuqhMg "After you identify the specific correlation rule and notable event type for the profile, the next step is to map individual notable event fields to the fields on a ServiceNow AI Platform Security Incident Response (SIR) security incident.") and [Map notable events](https://servicenow-prod.fluidtopics.net/S8Q5JE6V8DjCGdcO_0DVkg "During the notable event field-mapping step, you map individual event fields from notable events to fields on a ServiceNow AI Platform Security Incident Response (SIR) security incident."). |
   | 6. | * As a user with the ServiceNow AI Platform sn_si.ingestion_profile_admin role, preview the data from Splunk Enterprise that is displayed on a ServiceNow AI Platform security incident. * Fix any errors or add any missing data so that no error messages are displayed. {#splunk-event-ingest-checklist-security__ul_f3m_hjp_dhb} For more information, see [Preview security incident](https://servicenow-prod.fluidtopics.net/tlAekcp9oiqAvnlFmHL0Lw "After you complete the mapping step, preview the values that you mapped in a ServiceNow AI Platform Security Incident Response (SIR) security incident. This preview step permits you to verify that you have mapped all the notable fields that you want displayed on the security incident."). |
   | 7. | As a user with the ServiceNow AI Platform sn_si.ingestion_profile_admin role, schedule alert retrieval for a profile with a scheduled alert. For more information, see [Schedule and retrieve notable events](https://servicenow-prod.fluidtopics.net/6IDa1YGM4R4SN5ikq0bcTQ "For automated notable event ingestion profiles, this step is required in the event profile configuration. During this step, you can verify the default settings for notable event retrieval or modify the scheduling as needed. This step also permits you to retrieve historical notable events using a date range."). |
   [Table 1. Checklist]

   {#splunk-event-ingest-checklist-security__table_f2c_xn4_sgb}  
   You have successfully completed the setup steps and verified expected results for the integration.
{#splunk-event-ingest-checklist-security__steps_ikm_c32_sgb}

