---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Using Splunk add-on

# Using ServiceNow Security Operations Integration add-on {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Create security events and incidents directly from Splunk alerts after setting up ServiceNow Security Operations Integration add-on.

## Before you begin

Role required: sn_si.integration_user, sn_si.analyst

## Procedure

1. Log in to [Splunk Enterprise](https://splunk.secops-eng.com:8000/en-GB/app/launcher/home).
2. Navigate to AppsSearch \& Reporting.
3. Enter a keyword in the New Search field.  
   A list of events with the keyword show up.
4. Expand any of the events using (\>) icon.
5. Select Event Actions.  
   * Create ServiceNow Security Event: Events are stored in the em_event table.  
     Note:  
     Install Event Management plugin to access the em_event table.
   * Create ServiceNow Security Incident: Incidents are stored in the sn_si_incident table.  
     Note:  
     The mapping is pre defined as we don't have a profile for this add-on.

   {#using-sn-secops-int-addon__ul_bmb_21y_wgc}

*[\>]: and then


