---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Set up

# Set up your ServiceNow AI Platform instance for the Splunk Enterprise Event Ingestion integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

The following section lists the setup tasks that you are required to complete in your
ServiceNow AI Platform® instance prior to installing the application from the
ServiceNow Store.

## Before you begin

Role required: admin

## About this task

Refer to the following table and verify that you have completed all the listed tasks
before you download and install the application to ensure a smooth installation and
configuration.

## Procedure

1. Verify that you have assigned the required ServiceNow AI Platform® and Security Incident Response (SIR) roles.  
   The following roles are required for the installation, setup, and use of the
   integration in your ServiceNow AI Platform® instance.
   * A user with the ServiceNow AI Platform® administrator role (admin) installs the application from the ServiceNow Store and assigns the security incident administrator (sn_si.admin) role.
   * If you want to forward events manually from Splunk Enterprise for this integration, a user with the ServiceNow AI Platform® admin role assigns a user with the (sn_sec_splunk_v2.api_account_access) role in the ServiceNow AI Platform®. This role permits a user with the Splunk Enterprise administrator role to access the API in the ServiceNow AI Platform® that is required for manual event forwarding for this integration.

     The (sn_sec_splunk_v2.api_account_access)
     role is not required for the integration if you are ingesting alerts
     automatically from Splunk Enterprise into your ServiceNow AI Platform® instance.
   * A user with the sn_si.ingestion_profile_admin role oversees the following tasks in the ServiceNow AI Platform®:
     * Names, creates, and edits alert and event profiles.
     * Selects and maps values from alerts and events to ServiceNow AI Platform® security incidents.
     * Previews security incident details for accuracy prior to finalizing the configuration.
     * Schedules on-going alert ingestion.
     * Assigns the security incident analyst (sn_si.analyst) role.
     * Users with the sn_si.analyst work with security incidents.
     {#splunk-event-ingest-setup-sn__ul_gvy_hpv_3fb}

   {#splunk-event-ingest-setup-sn__ul_fvy_hpv_3fb}

   For more information about roles and assigning roles to users, see [Managing roles](https://www.servicenow.com/docs/access?context=ua-creating-roles&version=australia&pubname=australia-platform-administration&ft:locale=en-US).
2. Verify that you are using version 6.0 or later of the Splunk API.  
   If you have access to the Splunk Enterprise console, you have
   access to the API that is required for this integration. There is no other special
   setup required for the API.
3. Verify that you have installed and configured a MID Server.  
   A MID Server in your ServiceNow AI Platform® instance is required to
   connect to the Splunk service if the Splunk
   server is deployed within your corporate network. For more information about MID
   servers, see [MID Server](https://www.servicenow.com/docs/access?context=mid-server-landing&version=australia&pubname=australia-servicenow-platform&ft:locale=en-US)

   If you are using the Splunk Cloud service, a MID Server is not
   required.
4. Verify that the ServiceNow core applications required to support the integration are installed and activated.  
   The Security Incident Response Dependency plugin (com.snc.si_dep) is
   required. This plugin automatically installs all the dependencies that are
   required to support the Security Incident Response product. Install and
   activate this plugin before you install and activate the other Security Operations applications required by the integration.

   Verify that the following Security Operations applications are installed
   and activated from the ServiceNow Store. If not installed, install
   and activate one application at a time in the following order to ensure a smooth
   installation.  
   1. Security Incident Response
   2. Security Integration Framework
   3. Security Support Common
   4. Security Support Orchestration
   {#splunk-event-ingest-setup-sn__ol_qwy_vrt_fhb}

   For more information about installing the Security Operations core
   applications, see [Get entitlement for a Security Operations product or application](https://servicenow-prod.fluidtopics.net/ZZVMDPCDs~BwBGv0OAhjuA "The first step in installing a Security Operations application is to verify that the application or the product and its associated applications have valid ServiceNow entitlements.") and [Activate a ServiceNow Store application](https://servicenow-prod.fluidtopics.net/RFo48XO5_M32aNft7_tP2A "After an application has been given entitlement, you must activate its dependencies plugin and activate the application. This process also applies to applications downloaded to sub-production instances.").
{#splunk-event-ingest-setup-sn__steps_wvw_4n2_nsb}

## What to do next

You have successfully set up your ServiceNow AI Platform® instance for the integration. The next step is to install the Splunk Enterprise Event Ingestion application from the ServiceNow Store for the integration. For more information, see [Install and configure the ServiceNow application for the Splunk Enterprise Event Ingestion integration](https://servicenow-prod.fluidtopics.net/iTPEi_z_Av_gWCiaePdlrA "Install and configure Splunk Enterprise security- Event Ingestion integration from the ServiceNow Store on your ServiceNow AI Platform instance.").

If you have not saved searches in your Splunk Enterprise console
for ingestion, or if you are performing the initial setup for this integration in your
Splunk Enterprise console and the Security Operations
product of your ServiceNow AI Platform® instance simultaneously, see [Save searches in your Splunk Enterprise console for the Splunk Enterprise Event Ingestion integration](https://servicenow-prod.fluidtopics.net/0VDphX3DlcGaqk1W8jcgWQ "The following steps for saving searches in your Splunk Enterprise console are provided for a user with the Splunk Enterprise administrator role.") for
more information.

If you want to export events manually and on-demand from your Splunk Enterprise console for the integration, see [Set up ServiceNow Event Ingestion Integration add-on](https://servicenow-prod.fluidtopics.net/bilmNKpYai8R3CQx9ZTJmw "Install and set up the ServiceNow Event Ingestion Integration add-on in your Splunk enterprise console or Splunk Cloud instance.")
for more information.
**Previous topic:** [Splunk Enterprise Event Ingestion integration for Security Operations by ServiceNow](https://servicenow-prod.fluidtopics.net/hjqxnz8IumH15wispxbOhg "The Splunk Enterprise event and alert data integration with the Security Incident Response (SIR) product allows security incident analysts to collect and process security logs and related event data.")  
**Next topic:** [Install and configure the ServiceNow application for the Splunk Enterprise Event Ingestion integration](https://servicenow-prod.fluidtopics.net/iTPEi_z_Av_gWCiaePdlrA "Install and configure Splunk Enterprise security- Event Ingestion integration from the ServiceNow Store on your ServiceNow AI Platform instance.")

