---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure

# Install and configure the ServiceNow application for the Splunk Enterprise Event Ingestion integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Install and configure Splunk Enterprise security- Event Ingestion integration from the ServiceNow Store on your ServiceNow AI Platform instance.

## Before you begin

Role required: sn_si.ingestion_profile_admin  
Note:  
Users with the sn_si.admin role can perform all operations available to a profile admin, as the sn_si.admin role inherits the required permissions by default.

## Procedure

1. If you have not installed the Splunk Enterprise Event Ingestion application from the ServiceNow Store for the integration, see [Install a Security Operations integration](https://servicenow-prod.fluidtopics.net/dIzJWROPdytPu1FmtvPx3w "All ServiceNow integrations are available on the ServiceNow Store. Core applications, such as Security Incident Response, are visible in the ServiceNow Products tab on the store. Integration add-ons are visible in the Certified Apps tab.") and follow the steps to install it.
2. Navigate to AllIntegrationsIntegrations Configurations
3. Search for Splunk Enterprise security- Event Ingestion tile, and select Configure.
4. On the form, fill in the fields.

   | Field | Description |
   | Name | Name of the Splunk Enterprise console or Splunk Cloud instance used for the integration. Spaces are supported for names, but parentheses are not supported. For example, enter <kbd class="ph userinput">HQ-USA</kbd>, or <kbd class="ph userinput">HQ USA</kbd>. |
   | Splunk API Base URL | URL for your Splunk Enterprise console or Splunk Cloud instance. |
   | Basic Authentication | Default is disabled. If you are using API Account User Name and API Password for configuration, enable the check box. |
   | API Account User Name | User name that you created for your individual user account on the Splunk Enterprise console. |
   | API Password | Password that you created for your individual user account on the Splunk Enterprise console. |
   | Token Based (available from version 12.0.0) | Token based authentication that you created for your API user account on the Splunk Enterprise console. |
   | Token | Token that you created for your API user account on the Splunk Enterprise console. |
   | MID Server | Specific MID Server that is set up in your environment. Only MID Servers that are active and validated are available from this choice list. |
   | On Premises Deployment | Default is disabled. If you are using the cloud-based version of Splunk Enterprise, verify that the check box is cleared. If this option is enabled, the MID Server choice list is displayed. If you are using an on-premises version of Splunk Enterprise, follow these steps to select a MID Server. 1. Select the check box.A choice list is displayed. Default is Any. 2. Select Any only if this MID server is configured for the Splunk Enterprise Event Ingestion integration. 3. From the choice list, select the ServiceNow AI Platform® MID server that you configured in your instance for this specific integration. {#splunk-event-ingest-install-and-configure__ol_ulq_r4g_5gb} |
   |-|-|

   {#splunk-event-ingest-install-and-configure__choicetable_rrp_bwk_kdb}  
   Each Splunk Enterprise alert that you ingest from your Splunk Enterprise console requires a unique event profile in your ServiceNow AI Platform® instance. However, the source that you configure on the Event Ingestions Configuration form can be reused for multiple ServiceNow AI Platform® profiles as long as each profile ingests unique Splunk triggered alerts.
5. Select Submit.  
   The configured integration tile displays.
{#splunk-event-ingest-install-and-configure__steps_rvh_qsv_3fb} If an error message is displayed after you click Submit, enter
your information again and click Submit.

## What to do next

You have successfully installed and configured the application. The next step is to
create an event profile.
* **[Configure Splunk Enterprise Event Ingestion settings](https://servicenow-prod.fluidtopics.net/JSQvOf7QCHlZDs0~Tm0L7A)**   
  Use the Splunk Enterprise Event Ingestion settings to modify the preset configurations and their values as per your requirements.

**Previous topic:** [Set up your ServiceNow AI Platform instance for the Splunk Enterprise Event Ingestion integration](https://servicenow-prod.fluidtopics.net/WojQBjV4Cqd7eb~GLjunFA "The following section lists the setup tasks that you are required to complete in your ServiceNow AI Platform instance prior to installing the application from the ServiceNow Store.")  
**Next topic:** [Configure Splunk Enterprise Event Ingestion settings](https://servicenow-prod.fluidtopics.net/JSQvOf7QCHlZDs0~Tm0L7A "Use the Splunk Enterprise Event Ingestion settings to modify the preset configurations and their values as per your requirements.")

*[\>]: and then


