Configure and enable Splunk integration
Configure the Splunk Enrichment integration to automatically search your logs and add relevant sighting information to threat intelligence data.
Before you begin
Role required: sn_sec_tisc.admin
Important:
- Download the Splunk Search app from the ServiceNow Store to get started.
- Install and activate the Threat Intelligence Security Center plugin to enable the Splunk Search integration.
- From your Splunk instance, copy the API Base URL, Link URL, Username, and Password.
Procedure
What to do next
After you configure the integration, you can select Splunk to perform sighting searches on observables in Threat Intelligence Security Center.