---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Checklist

# Checklist for the Splunk Enterprise Event Ingestion integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Use this checklist to guide you through all the tasks of the integration. The
following checklist includes setup and installation tasks and examples of use cases that
include expected results for the integration.

## Before you begin

Role required: admin

## About this task

Track your progress with the setup, installation, and configuration of the integration
with the following table. Complete all the tasks for a step before moving on to the next
step. Each row of the table lists tasks and identifies the roles that are required to
perform the tasks. Numbered topics of the installation and configuration guide are also
referenced.

Roles required: Roles are listed for each step below.

## Procedure

1. As a user with the ServiceNow AI Platform admin role, set up your ServiceNow AI Platform instance.  
   * Assign users with the sn_si.ingestion_profile_admin (or sn_si.admin) and sn_si.analyst roles as required.
   * Install and configure a MID Server if the Splunk server is deployed within your corporate network.
   * Verify that the ServiceNow Security Incident Response plugins are activated for your release of the ServiceNow AI Platform.
   * If you want to forward events manually from your Splunk Enterprise console into your ServiceNow AI Platform instance, verify that you have assigned the (sn_sec_splunk_v2.api_account_access) role to a user with the Splunk Enterprise enterprise administrator permission.

   {#splunk-event-ingest_checklist__ul_q3c_wc2_ygb}

   For more information, see [Set up your ServiceNow AI Platform instance for the Splunk Enterprise Event Ingestion integration](https://servicenow-prod.fluidtopics.net/WojQBjV4Cqd7eb~GLjunFA "The following section lists the setup tasks that you are required to complete in your ServiceNow AI Platform instance prior to installing the application from the ServiceNow Store.").  
   You have successfully completed the set up steps and verified expected results for the integration.
2. As a user with the ServiceNow AI Platform admin role, install and configure the Splunk Enterprise Event Ingestion application from the ServiceNow Store.  
   1. Download and install the application on your ServiceNow AI Platform instance.
   2. Configure the application and connect to your Splunk Enterprise console.

   {#splunk-event-ingest_checklist__ol_o1m_k44_sgb}

   For more information, see [Install and configure the ServiceNow application for the Splunk Enterprise Event Ingestion integration](https://servicenow-prod.fluidtopics.net/iTPEi_z_Av_gWCiaePdlrA "Install and configure Splunk Enterprise security- Event Ingestion integration from the ServiceNow Store on your ServiceNow AI Platform instance.").
3. **Optional:** If you intend to export events manually from your Splunk Enterprise console to your ServiceNow AI Platform instance, perform the following tasks:
   1. As a Splunk Enterprise administrator, install, set up, and enable the ServiceNow Security Operations Event Ingestion Addon for Splunk Enterprise from splunkbase in your Splunk Enterprise console.
   2. As a Splunk Enterprise administrator, if not already configured, save searches as alerts in your Splunk Enterprise console.  
      For more information, see [Set up ServiceNow Event Ingestion Integration add-on](https://servicenow-prod.fluidtopics.net/bilmNKpYai8R3CQx9ZTJmw "Install and set up the ServiceNow Event Ingestion Integration add-on in your Splunk enterprise console or Splunk Cloud instance.") and [Save searches in your Splunk Enterprise console for the Splunk Enterprise Event Ingestion integration](https://servicenow-prod.fluidtopics.net/0VDphX3DlcGaqk1W8jcgWQ "The following steps for saving searches in your Splunk Enterprise console are provided for a user with the Splunk Enterprise administrator role.").
   {#splunk-event-ingest_checklist__substeps_tzy_ss2_nsb}
4. As a user with the ServiceNow AI Platform sn_si.ingestion_profile_admin role, create and name an event profile.  
   Select the profile type from the choice list. Options are a scheduled alert profile that you use to ingest sample data, or, an event profile that you use to export attachment data manually from your Splunk Enterprise console.
   * For a scheduled alert, select an available alert.
   * For profile for manually exported data, create a new map or copy an existing map.

   {#splunk-event-ingest_checklist__ul_ds4_w32_ygb}

   For more information, see [Create and name an event profile](https://servicenow-prod.fluidtopics.net/AWEnQ9DSqlXxPqTsIzzq4A "Create an event profile in your ServiceNow AI Platform instance and determine which Splunk alerts create security incidents.").
5. As a user with the ServiceNow AI Platform sn_si.ingestion_profile_admin role, map values ingested or attachment data that is exported from Splunk Enterprise to ServiceNow AI Platform security incidents.  
   1. Fetch sample data for a scheduled alert.
   2. Export attachment data manually from Splunk Enterprise for an event.
   3. Edit the default mapping configuration.
   4. Optionally add filtering criteria, append an alert to an existing security incident, and use the script editor.

   {#splunk-event-ingest_checklist__ol_rdf_dp4_sgb}

   For more information, see [Mapping alerts and events for the Splunk Enterprise Event Ingestion integration](https://servicenow-prod.fluidtopics.net/yxPDN3xjBD1T8F3U7HupWg "After you identify the sources for scheduled alert ingestion or manual event forwarding, the next step is to map individual event fields to the fields on a ServiceNow AI Platform Security Incident Response (SIR) security incident.") and [Map alerts for the Splunk Enterprise Event Ingestion integration](https://servicenow-prod.fluidtopics.net/s4v_~FyQFqoLnSsSJZ4_nA "During the event field-mapping step, you map individual event fields from triggered alerts or imported event data to fields on a ServiceNow AI Platform Security Incident Response (SIR) security incident.").
6. As a user with the ServiceNow AI Platform sn_si.ingestion_profile_admin role, preview the data from Splunk Enterprise that is displayed on a ServiceNow AI Platform security incident.  
   Fix any errors or add any missing data so that no error messages are displayed.

   For more information, see [Preview security incident for the Splunk Enterprise Event Ingestion integration](https://servicenow-prod.fluidtopics.net/IS8CoqSvyyEJs1eTn47BLw "After you complete the mapping step, preview the values that you mapped in a ServiceNow AI Platform Security Incident Response (SIR) security incident. This preview step permits you to verify that you have mapped all the alert fields that you want displayed on the security incident.").
7. As a user with the ServiceNow AI Platform sn_si.ingestion_profile_admin role, schedule alert retrieval for a profile with a scheduled alert.  
   For more information, see [Schedule and retrieve alerts for the Splunk Enterprise Event Ingestion integration](https://servicenow-prod.fluidtopics.net/QzEbpAlPeGW5QVBXYujLJQ "For automated alert ingestion profiles, this step is final step of the event profile configuration. During this step, you can verify the default settings for alert retrieval or modify the scheduling as needed. This step permits you to filter your alert retrieval based on a date range.").
{#splunk-event-ingest_checklist__steps_ikm_c32_sgb}

