Splunk® Supported Add-ons

Splunk Add-on for ServiceNow

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

Splunk Add-on for ServiceNow

Version 6.4.1
Vendor Products ServiceNow London, Madrid, New York, Orlando, and Paris
Add-on has a web UI Yes. This add-on contains views for configuration.

The Splunk Add-on for ServiceNow allows a Splunk software administrator to use ServiceNow REST APIs to collect the following types of data:

  • Incident data
  • Event data
  • Change data
  • User data
  • User group data
  • Location data
  • Configuration management database (CMDB) configuration item (CI) data


After you install and configure this add-on, you can use workflow actions that link directly from events in the Splunk platform search results to relevant ServiceNow incidents, events, and knowledge base articles. You can also use the custom commands, alert actions, and scripts to create new incidents and events in your ServiceNow instance, and update the incidents created from the Splunk platform.

For more information about this add-ons custom commands, alert actions, and scripts, see About the commands, alert actions, and scripts available with the Splunk Add-on for ServiceNow. This add-on provides the inputs and CIM-compatible knowledge to use with other Splunk apps, such as the Splunk App for ServiceNow or Splunk Enterprise Security.

Download the Splunk Add-on for ServiceNow from Splunkbase.

For a summary of new features, fixed issues, and known issues, see Release Notes for the Splunk Add-on for ServiceNow.

For information about installing and configuring the Splunk Add-on for ServiceNow, see Installation and configuration overview for the Splunk Add-on for ServiceNow.

See the Splunk Community page for questions related to Splunk Add-on for ServiceNow.

Last modified on 11 March, 2021
  NEXT
Source types for the Splunk Add-on for ServiceNow

This documentation applies to the following versions of Splunk® Supported Add-ons: released, released


Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters