---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Forward events on-demand

# Using ServiceNow Security Operations Event Ingestion Add-on for Splunk ES {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Forward events on-demand from your Splunk Enterprise Security console to create a Security Incident Response (SIR) on the ServiceNow instance.

## Before you begin

Role required: sn_sec_splunkes.api_account_access

## Procedure

1. Log in to [Splunk Enterprise](https://splunk.secops-eng.com:8000/en-GB/app/launcher/home).
2. Navigate to AppsEnterprise Security.
3. Select Mission Control.  
   A list of notable events generated in the Splunk console on the basis of correlation rule configured previously show up.
4. Select any Notable Event from the list.
5. Select Ellipsis icon (⋮).
6. From the drop down, select the Workflow action label configured while setting up the add-on.  
   For more information on Workflow action label, see [Setup ServiceNow Security Operations Event Ingestion Addon for Splunk ES](https://servicenow-prod.fluidtopics.net/Yw_rroi7C7Gkp78D_uwvRA "The ServiceNow Security Operations Event Ingestion Add-on for Splunk ES enables seamless integration between Splunk and ServiceNow Security Operations, allowing you to send security-related events from Splunk to ServiceNow security incident. For detailed instructions on downloading and installing the Addon, follow the steps outlined in this guide.")  
   Events will go in Splunk ES Event Import table followed by Splunk ES Event to Tasks table.

## Result

A Security Incident Response (SIR) record is created on the ServiceNow instance as per the mapping specified in the Manual event forwarding profile. For instructions on how to set up a Manual event forwarding profile, see [Create and name an event profile](https://servicenow-prod.fluidtopics.net/AWEnQ9DSqlXxPqTsIzzq4A "Create an event profile in your ServiceNow AI Platform instance and determine which Splunk alerts create security incidents.")

*[\>]: and then


