---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Splunk Enterprise Event Ingestion integration for Security Operations by ServiceNow

# Splunk Enterprise Event Ingestion integration for Security Operations
by ServiceNow {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Splunk Enterprise Event Ingestion integration for Security Operations by ServiceNow

The Splunk Enterprise Event Ingestion integration with ServiceNow Security Incident Response (SIR) enables real-time collection and processing of security logs and event data.
This integration helps security analysts detect, report, and investigate potential cyber threats by automatically ingesting triggered alerts and manually forwarding individual security events from Splunk Enterprise into ServiceNow's AI Platform.
It supports retrieving notable events using Splunk search head cluster configurations and provides SOC analysts with enhanced visibility by integrating event and alert data into SIR security incidents for streamlined investigation and remediation.
Show full answer Show less  
Profiles within ServiceNow customize how Splunk alert and event fields appear on SIR incidents, with default mappings that can be edited to suit specific customer requirements.

## Key Features

* Create multiple alert ingestion profiles tailored to specific threat types such as phishing and malware.
* Create event profiles for on-demand forwarding of events from Splunk to ServiceNow SIR incidents.
* Drag-and-drop interface for mapping Splunk alert and event fields to SIR incident fields, including a preview feature to validate configurations.
* Ingest both historical and ongoing alerts on configurable intervals.
* Aggregate events or alerts to existing SIR incidents by matching field values to prevent duplicate incident creation.

## Requirements and Compatibility

* The **com.snc.sidep** plugin is required to support the Security Incident Response product and its dependencies; it must be installed before other Security Operations applications.
* Security Operations applications must be installed and activated in a specific sequence to ensure proper functionality: Security Integration Framework, Security Support Common, Security Support Orchestration, then Security Incident Response.
* The ServiceNow Security Operations Event Ingestion Addon for Splunk Enterprise (available on Splunkbase) is required only for manual event forwarding; it is not necessary for automated alert ingestion.
* The integration supports Splunk Enterprise version 6.0 or later, including Splunk Enterprise Cloud.
* A configured MID Server is required when Splunk is deployed on-premises within a corporate network to facilitate connectivity; no MID Server is needed for Splunk Cloud service.

## Installation and Setup

To deploy this integration, customers must prepare their ServiceNow AI Platform instance by completing prerequisite setup tasks before installing the integration application from the ServiceNow Store. This includes creating and naming event profiles to define how Splunk alerts generate security incidents in ServiceNow. Following the prescribed installation order of Security Operations applications ensures a smooth configuration process.

## Integration Architecture

The integration architecture supports ingesting triggered alerts from Splunk Enterprise into ServiceNow, clarifying the conceptual operation and necessary setup steps. It ensures efficient connection between external systems and ServiceNow AI Platform for seamless security event processing.  
The Splunk Enterprise event and alert data integration with the Security Incident Response (SIR) product allows
security incident analysts to collect and process security logs and related event
data.

## Overview of Splunk Enterprise Event Ingestion {#splunk-event-ingest-overview__section_aqv_bhj_jfb}

Data is collected in real-time, and it is used by analysts to identify and report on
potential cyber threats. The security events that are collected can be processed into
triggered alerts that are ingested automatically with this integration. Also, individual
security events can be manually forwarded on-demand from the Splunk Enterprise search and reporting interface into the Security Incident Response product of the ServiceNow AI Platform to create
security incidents. You can retrieve notable events from Splunk Enterprise search with the search head cluster configuration.
You can achieve this by using the URL and API port of any search head that is a part of
the cluster.

This integration provides a security operations center (SOC) analyst with visibility to
events and related alert data. This data can be integrated into ServiceNow AI Platform
Security Incident Response (SIR) security
incidents for further investigation and remediation. Profiles for Splunk ongoing ingested alerts and forwarded events are created in
your ServiceNow AI Platform instance. These profiles customize how different Splunk alert and event fields are displayed on SIR security incidents. A default mapping of alert
fields is provided that can be edited and augmented to meet customer-specific needs.

## Key features {#splunk-event-ingest-overview__section_irs_fhj_jfb}

This integration includes the following key features:

* Create multiple alert ingestion profiles to create SIR security incidents for specific types of threats such as phishing and malware.
* Create multiple event profiles for on-demand event forwarding from your Splunk console to create SIR security incidents.
* Drag-and-drop mapping of Splunk alert and event field values to associated SIR security incident fields.
* A preview of the SIR security incident layout based on sample alerts or events to validate profile configuration.
* Ingest historical alerts as well as ongoing, future alerts on configurable intervals.
* Aggregate events or alerts to existing SIR security incidents based on matching field values to avoid duplicate security incidents.
{#splunk-event-ingest-overview__ul_jzw_t3j_jfb}

## Supported ServiceNow AI Platform versions {#splunk-event-ingest-overview__section_x15_vjm_y2b}

The com.snc.si_dep plugin is required. This plugin automatically installs all the dependencies that are required to support the Security Incident Response product. Install and activate this plugin before installing and activating the other Security Operations applications.  
The following Security Operations applications must be installed and activated from the ServiceNow Store. Install and then activate one application at a time in the order listed below to ensure a smooth installation:

1. Security Integration Framework
2. Security Support Common
3. Security Support Orchestration
4. Security Incident Response
{#splunk-event-ingest-overview__ol_xcx_jzk_tgb}

For more information about installing the Security Operations core applications,
see [Get entitlement for a Security Operations product or application](https://servicenow-prod.fluidtopics.net/ZZVMDPCDs~BwBGv0OAhjuA "The first step in installing a Security Operations application is to verify that the application or the product and its associated applications have valid ServiceNow entitlements.") and [Activate a ServiceNow Store application](https://servicenow-prod.fluidtopics.net/RFo48XO5_M32aNft7_tP2A "After an application has been given entitlement, you must activate its dependencies plugin and activate the application. This process also applies to applications downloaded to sub-production instances.").

## ServiceNow Addons {#splunk-event-ingest-overview__section_sw3_mqb_2gb}

The ServiceNow Security Operations Event Ingestion Addon for
Splunk Enterprise is required only if you prefer to forward events
manually from your Splunk Enterprise console into your ServiceNow AI Platform instance. This ServiceNow addon is
available in [splunkbase](https://splunkbase.splunk.com/).

This ServiceNow Security Operations Event Ingestion Addon for
Splunk Enterprise application in splunkbase is not required for
the automated alert ingestion that is supported by the integration.

## Splunk Supported versions {#splunk-event-ingest-overview__section_j25_1jm_y2b}

This integration supports version 6.0 or later of Splunk Enterprise. The integration also supports the Splunk Enterprise Cloud service.

## MID Server {#splunk-event-ingest-overview__section_e2y_5rb_2gb}

This integration requires an installed and configured MID Server in your ServiceNow AI Platform® instance to connect to the Splunk
service if the Splunk server is deployed within your corporate
network. If you are using the Splunk Cloud service, a MID Server is
not required. For more information about MID Servers, see [MID Server](https://www.servicenow.com/docs/access?context=mid-server-landing&version=australia&pubname=australia-servicenow-platform&ft:locale=en-US).

## Integration architecture and systems connection {#splunk-event-ingest-overview__section_j33_ghf_dhb}

For more information about the architecture of the integration including key terms and
external systems connection details, see [Integration architecture and external systems connection](https://servicenow-prod.fluidtopics.net/f15RDhB0geWAFIby47odRQ "The following topic outlines the integration architecture developed to support the ingestion of triggered alerts from the Splunk Enterprise console. This information clarifies, at a high level, the conceptual operation of the integration. It also explains why there are setup steps that are required prior to installing the application from the ServiceNow Store.").

## Checklist {#splunk-event-ingest-overview__section_gpy_lhf_dhb}

For a printable checklist of these topics, see [Checklist for Splunk Enterprise Security Notable Event Ingestion integration](https://servicenow-prod.fluidtopics.net/8X3~BoOXPuGZh34S786cCQ "Use this checklist to guide you through all the tasks of the integration. The following checklist includes setup and installation tasks and examples of use cases that include expected results for the integration."). You can
use this list to monitor your progress as you work through the tasks of the
integration.

The images used in the following topics were generated for the Kingston release of the
ServiceNow AI Platform. For information about the San Diego user interface, see
[Manage security threats using the Security Analyst Workspace](https://servicenow-prod.fluidtopics.net/ivFWY8MwE4YqB1jSs6JKFg "Security Incident Response includes a new user interface called the Security Analyst Workspace that features powerful tools for assisting in analysis, including the playbook, peek view, and tabs for working on multiple security incidents.").

The following topics are numbered. Follow the topics listed below in the order that they
are presented for a smooth installation and configuration of the application.
1. [Set up your ServiceNow AI Platform instance for the Splunk Enterprise Event Ingestion integration](https://servicenow-prod.fluidtopics.net/WojQBjV4Cqd7eb~GLjunFA)  
   The following section lists the setup tasks that you are required to complete in your ServiceNow AI Platform® instance prior to installing the application from the ServiceNow Store.
2. [Install and configure the ServiceNow application for the Splunk Enterprise Event Ingestion integration](https://servicenow-prod.fluidtopics.net/iTPEi_z_Av_gWCiaePdlrA)  
   Install and configure Splunk Enterprise security- Event Ingestion integration from the ServiceNow Store on your ServiceNow AI Platform instance.
3. [Create and name an event profile](https://servicenow-prod.fluidtopics.net/AWEnQ9DSqlXxPqTsIzzq4A)  
   Create an event profile in your ServiceNow AI Platform instance and determine which Splunk alerts create security incidents.
4. [Integration architecture and external systems connection](https://servicenow-prod.fluidtopics.net/f15RDhB0geWAFIby47odRQ)  
   The following topic outlines the integration architecture developed to support the ingestion of triggered alerts from the Splunk Enterprise console. This information clarifies, at a high level, the conceptual operation of the integration. It also explains why there are setup steps that are required prior to installing the application from the ServiceNow Store.

