---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Use Splunk add-on

# Using ServiceNow Event Ingestion Integration add-on {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Map alerts from Splunk console to create a Security Incident Response (SIR) on the ServiceNow instance.

## Before you begin

Role required: sn_sec_splunk_v2.api_account_access

## Procedure

1. Log in to [Splunk Enterprise](https://splunk.secops-eng.com:8000/en-GB/app/launcher/home).
2. Navigate to AppsSearch \& Reporting.
3. Select Alerts.  
   A list of alerts generated in the Splunk console on the basis of correlation rule configured previously show up.
4. Select any Configured Alert from the list.  
   Trigger History of the configured alert show up.
5. Select View Results against the alert.
6. Expand any of the alerts using (\>) icon.
7. From the drop down, select the Workflow action label configured while setting up the add-on.  
   For more information on Workflow action label, see [Set up ServiceNow Event Ingestion Integration add-on](https://servicenow-prod.fluidtopics.net/bilmNKpYai8R3CQx9ZTJmw "Install and set up the ServiceNow Event Ingestion Integration add-on in your Splunk enterprise console or Splunk Cloud instance.")  
   Alerts will go in Splunk Import table followed by Splunk Event to Tasks table.

## Result

A Security Incident Response (SIR) record is created on the ServiceNow instance as per the mapping specified in the Manual event forwarding profile. For instructions on how to set up a Manual event forwarding profile, see [Create and name an event profile](https://servicenow-prod.fluidtopics.net/AWEnQ9DSqlXxPqTsIzzq4A "Create an event profile in your ServiceNow AI Platform instance and determine which Splunk alerts create security incidents.")

*[\>]: and then


