---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# TISC add-on for Splunk overview

# TISC add-on for Splunk overview {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Configure the Threat Intelligence Security Center (TISC) integration with Splunk to import threat intelligence data, set up indicator collections, and analyze search matches using dashboards.
* **[TISC integration with Splunk](https://servicenow-prod.fluidtopics.net/TrT3yV3JQRhv7CCQ0xdJtQ)**   
  The integration between the Threat Intelligence Security Center (TISC) and Splunk lets you filter and pull relevant threat intelligence observables data into Splunk.In Splunk, you can use this data to generate security alerts.
* **[Create users in TISC instance](https://servicenow-prod.fluidtopics.net/0KDLTfVq12B7L6orD~Iebg)**   
  Users can be created in the ServiceNow TISC instance with any valid user role \[`sn_sec_tisc.api_obs_read_access]`.
* **[Configure TISC add-on in Splunk](https://servicenow-prod.fluidtopics.net/eGDCRjLSe5DcQnmzBfqjVg)**   
  Configure the TISC add-on in Splunk to connect your account, define data inputs, and pull observable records into the KV store for search and analysis.
* **[Data storage in Splunk](https://servicenow-prod.fluidtopics.net/IbcEMdLHbvrVXX8GI_TyTA)**   
  Configure and retrieve Key-Value store lookups used by TISC during its integration with Splunk.
* **[Troubleshoot the TISC add-on in Splunk](https://servicenow-prod.fluidtopics.net/KWOMIJru9a1AqP7zrWYGcw)**   
  Enable debug logging on the add-on, view the resulting log entries in Splunk, and check input execution status from the Input Metadata Lookup KV store.

