---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Splunk - Incident Enrichment integration

# Splunk - Incident Enrichment integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Splunk - Incident
Enrichment integration searches your logs and adds relevant sighting information to your
security incidents.

|-|-|
| Explore [Security Incident Response integrations](https://servicenow-prod.fluidtopics.net/RhaRoT0Fn_2fkoMqo0mGDA "Security Incident Response (SIR) integrates with third-party security tools to create security incidents.") | Setup [Get started with the Splunk Search integration for Security Operations](https://servicenow-prod.fluidtopics.net/J~Ap572iPMD~WNPHWTYjpQ "Splunk software searches, monitors, and analyzes machine-generated big data and integrates easily with Security Operations. Before you can use the Splunk - Incident Enrichment integration, you must download it from the ServiceNow Store and add the appropriate API Base URL and login credentials.") |
| Use * [Run a Sightings Search](https://servicenow-prod.fluidtopics.net/PhrwoCC1EliI1442kisZFw "Determine the prevalence of a threat over time or test remediation or eradication efforts. You can select individual or multiple observables and the date range for your search from a security incident. Results are included in the Security Incident Observables related list.") * [Security Operations Integration - Sightings Search Flow](https://servicenow-prod.fluidtopics.net/h_dAICTJQ0lbJ~eF~zxSLA "Security Operations Integration - Sightings Search flow is a high-level flow independent of integrations. It uses the configured queries to search for a set of observables based on the configured integrations which support the capability. Use it to fulfill an integration such as Splunk or Elasticsearch.") * [Security Operations Integration - Splunk Sightings Search Flow](https://servicenow-prod.fluidtopics.net/X07OwZ_Zwy~i_9~Y9lYjww "Security Operations - Splunk Sightings Search flow is the implementation for the Splunk integration launched by the Security Operations Integration - Sightings Search flow.") * [View Sightings Search Details](https://servicenow-prod.fluidtopics.net/30fRGbtB5hByCzMuxWAS~Q "Review the aggregate details of all sighting searches.") * [View Sightings Search Results](https://servicenow-prod.fluidtopics.net/Lu11DWRNYB~z1UzlENAuSw "You can review Sightings Search Results for internal and external malicious indicators.") {#splunk-in-enrich-landing-page__ul_qkh_cpj_dx} | Develop * [ServiceNow Security Operations integration development guidelines](https://servicenow-prod.fluidtopics.net/bvG2Jf6vlu8fw3IEOvGdMg "The ServiceNow platform provides several mechanisms for developing integrations with external systems. The ServiceNow Security Operations product suite adds integration capabilities intended to streamline the process of integrating with security-focused external systems.") * [Tips for writing integrations](https://servicenow-prod.fluidtopics.net/WrftS4_aOuJx7CfDqNBj1g "Avoid some of the pitfalls you can encounter when writing your own integrations by following these guidelines.") * [Developer training](https://developer.servicenow.com/app.do#!/training/landing) * [Developer documentation](https://developer.servicenow.com/app.do#!/documentation) * [Find components installed with an application](https://www.servicenow.com/docs/access?context=find-components&version=australia&pubname=australia-platform-administration&ft:locale=en-US) {#splunk-in-enrich-landing-page__ul_zsn_wnv_qx} |
| Troubleshooting and Additional information * [Integration troubleshooting](https://servicenow-prod.fluidtopics.net/_DwvxRbS3tQogK5A_dB8UQ "These troubleshooting suggestions can help you resolve common issues you can encounter when setting up or running integrations.") * [Ask or answer questions in the Security Operations community](https://community.servicenow.com/community/security-operations) * [Search the Known Error Portal for known error articles](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB0597477) * [Contact Customer Service and Support](https://support.servicenow.com/now?draw=case) {#splunk-in-enrich-landing-page__ul_zyk_3j4_qx} |   |
[Table 1.]

{#splunk-in-enrich-landing-page__simpletable_g33_wwg_vt}

