---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Set up Splunk environment

# Set up ServiceNow Event Ingestion Integration add-on {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Install and set up the ServiceNow Event Ingestion Integration add-on in your Splunk enterprise console or Splunk Cloud instance.

## Before you begin

Important:  
Create a Manual event forwarding profile to forward alerts on-demand from your splunk console to create a Security Incident Response (SIR) on the ServiceNow instance. For more information, see [Create and name an event profile](https://servicenow-prod.fluidtopics.net/AWEnQ9DSqlXxPqTsIzzq4A "Create an event profile in your ServiceNow AI Platform instance and determine which Splunk alerts create security incidents.") and implement same for Splunk V2.

This add-on setup is necessary to enable manual event forwarding for the Splunk profile. Up-to two configurations can be created for a particular add-on. (Splunk Primary and Splunk Secondary)

Verify that you have installed the application for this integration from the ServiceNow Store before installing the add-on plugin from splunkbase that is required for manual event ingestion. If you have not installed the application for the integration from the ServiceNow Store, see [Install and configure the ServiceNow application for the Splunk Enterprise Event Ingestion integration](https://servicenow-prod.fluidtopics.net/iTPEi_z_Av_gWCiaePdlrA "Install and configure Splunk Enterprise security- Event Ingestion integration from the ServiceNow Store on your ServiceNow AI Platform instance.") and follow the instructions to install it.

Role required: ServiceNow AI Platform administrator (admin)

## About this task

If you want to export events manually and on-demand from your Splunk console for the integration, download, and set up the ServiceNow Event Ingestion Integration add-on from Splunkbase in your Splunk console.

This ServiceNow extension add-on is required so that security incidents can be created from manually exported events in your ServiceNow AI Platform instance. This ServiceNow Event Ingestion Integration add-on is available on [splunkbase](https://splunkbase.splunk.com/).

For manual event forwarding, you can identify up to two different ServiceNow AI Platform endpoints (instances) in your Splunk Enterprise console. You forward the events to the endpoint or
endpoints manually to create security incidents. For example, you can specify both a
staging (development) instance and a production instance. By specifying separate
instances and naming primary and secondary workflows for each instance, you can choose
where you want to forward different events.

## Procedure

1. If you have not already installed the ServiceNow Event Ingestion Integration add-on, follow these steps to install and configure it.
   1. Download ServiceNow Event Ingestion Integration add-on from [Splunkbase](https://splunkbase.splunk.com/).
   2. If prompted, restart the Splunk Enterprise.  
      The ServiceNow Event Ingestion Integration add-on is installed in your Splunk Enterprise enterprise console. The next step is to set up the Add-on.
   {#splunk-event-ingest-setup-prereqs__substeps_cbg_pqf_wgb}
2. To set up the Addon, follow these steps.
   1. In the [Splunk Enterprise](https://splunk.secops-eng.com:8000/en-GB/app/launcher/home), select Manage Apps gear icon on the menu drop-down list.
   2. On the list of applications that is displayed, in the Actions column, select Set up for ServiceNow Event Ingestion Integration.  
      The ServiceNow Event Ingestion Integration add-on is configured into three different tabs.
      * Splunk Primary: The default or primary Splunk configuration.
      * Splunk Secondary: (Optional) The backup or second Splunk configuration.
      * Logging Level: The level of reporting logs generated by the integration, meaning the name of the type of information.
      {#splunk-event-ingest-setup-prereqs__ul_hns_hz1_hwb}
   3. On the form, fill in the fields.  
      {#splunk-event-ingest-setup-prereqs__table_evw_xjl_gxc__entry__2}

      | Field | Description |
      |-|-|
      | Workflow action label | Name of the instance. This will be an action in the drop-down of Event Actions for alerts in the Splunk console. |
      | URL | URL of the ServiceNow instance you entered in the preceding workflow action label field. |
      | Endpoint | Base API path. Default for this field is: /api/sn_sec_splunk_v2/event_ingestion. |
      | Auth type | Authentication method to be used for API requests. The available options include: * Basic Authentication: Uses username and password to authenticate requests. * OAuth 2.0 Authentication: Uses access tokens to authenticate requests. {#splunk-event-ingest-setup-prereqs__ul_ps2_dds_5gc} |
      | Basic Authentication ||
      | Username | Username of the user. User with the (sn_sec_splunk_v2.api_account_access) role should be present in the instance specified in the preceding URL field for manual event forwarding. |
      | Password | Password of the user. User with the (sn_sec_splunk_v2.api_account_access) role should be present in the instance specified in the preceding URL field for manual event forwarding. |
      | OAuth 2.0 Authentication ||
      | Client Id | Client ID of the app created in the ServiceNow instance. For information on how to get the Client ID, see [Configure Application Registry on the ServiceNow instance](https://servicenow-prod.fluidtopics.net/3nbvNEQ1CWNpuIeT2_nrvg "Register the application with the instance to use OAuth authorization."). |
      | Client Secret | Client Secret of the app created in the ServiceNow instance. For information on how to get the Client Secret, see [Configure Application Registry on the ServiceNow instance](https://servicenow-prod.fluidtopics.net/3nbvNEQ1CWNpuIeT2_nrvg "Register the application with the instance to use OAuth authorization."). |
      | Redirect URL | Copy and paste this URL in the redirect URL field of the Application Registries record. |
      [ ]

      {#splunk-event-ingest-setup-prereqs__table_evw_xjl_gxc}

   4. Select Save.
   5. Select the Splunk Secondary tab.
   6. On the form, fill in the fields.  
      Fields are same as in the Splunk Primary tab.
   7. Select Save.  
      Note:  
      Up-to two configurations can be created for a particular add-on.(Basic Authentication and another OAuth 2.0 Authentication)
   8. Select the Logging Level tab.
   9. On the form, fill in the fields.  
      {#splunk-event-ingest-setup-prereqs__table_b4q_pgp_vgc__entry__2}

      | Field | Description |
      |-|-|
      | Log Level | The level of reporting logs generated by the integration, meaning the name of the type of information. You can also update the value to the following options: * info * error * warn * debug {#splunk-event-ingest-setup-prereqs__ul_xnz_rgp_vgc} By default, the value is info. |
      [Table 1. Logging level]

      {#splunk-event-ingest-setup-prereqs__table_b4q_pgp_vgc}
   10. Select Save.
   {#splunk-event-ingest-setup-prereqs__substeps_yf4_fxf_wgb}

## What to do next

[Using ServiceNow Event Ingestion Integration add-on](https://servicenow-prod.fluidtopics.net/adQQYrmU2~rBnVmEIEquzA "Map alerts from Splunk console to create a Security Incident Response (SIR) on the ServiceNow instance.")

