Splunk® Supported Add-ons

Splunk Add-on for ServiceNow

Download manual as PDF

Download topic as PDF

Release notes for the Splunk Add-on for ServiceNow

Version 5.0.0 of the Splunk Add-on for ServiceNow was released on October 21, 2019.

Compatibility

Version 5.0.0 of the Splunk Add-on for ServiceNow is compatible with the following software, CIM versions, and platforms:

Splunk platform versions 7.0.x, 7.1.x, 7.2.x, 7.3.x, 8.0.0
CIM 4.12
Supported OS for data collection Platform Independent
Vendor products ServiceNow Kingston, London, Madrid, and New York

Upgrade

To upgrade from 3.1.0 or earlier to version 4.0.0 and above of the Splunk Add-on for ServiceNow, follow these steps:

  1. Before upgrading, disable the inputs configured in Splunk Add-on For ServiceNow version 3.1.0 or earlier.
  2. Upgrade the add-on.
  3. In the Splunk Add-on For ServiceNow > Configuration > ServiceNow Account tab, reconfigure your previously configured ServiceNow account.
  4. Go to the Splunk Add-on For ServiceNow > Inputs page, where there is a list of inputs that had been configured before the upgrade. The Table to collect data from field contains the values for all 23 table names. At first, all preconfigured inputs have a warning symbol in the Account column that indicates Missing Account configuration.
  5. Reconfigure each input:
    1. Select the correct ServiceNow account.
    2. (Optional) Edit the Interval field if required.
    3. Click Save.
  6. Enable the reconfigured inputs.

New features

Version 5.0.0 of the Splunk Add-on for ServiceNow includes the following new feature:

  • Support for Python 3.

Fixed issues

Version 5.0.0 of the Splunk Add-on for ServiceNow has the following known issues. If no issues appear below, no issues have yet been reported:


Known issues

Version 5.0.0 of the Splunk Add-on for ServiceNow has the following known issues. If no issues appear below, no issues have yet been reported:


Third-party software attributions

Version 5.0.0 of the Splunk Add-on for ServiceNow incorporates the following third-party software libraries:

PREVIOUS
Source types for the Splunk Add-on for ServiceNow
  NEXT
Release history for the Splunk Add-on for ServiceNow

This documentation applies to the following versions of Splunk® Supported Add-ons: released


Comments

When updating from 3.1.0 to 4.x, because you must disable all of the current inputs and reconfigure them, does that also mean that the `since_when` value needs to be adjusted to the last event timestamps for each table?

Will re-enabling the inputs as they exist in the prepopulated list after upgrading cause duplicate event data to be ingested? Editing an input will reset the checkpoint, so are any extra steps necessary related to setting the appropriate definitions?

Rcwood
July 3, 2019

Thanks for the clarification, @Ansif! I've removed mention of London from the New Features section.

Jbalik splunk, Splunker
March 19, 2019

@Jbalik : What I mean is under "New Feature" splunk docs mentioned London version is supported:

New features
Version 3.1.0 of the Splunk Add-on for ServiceNow includes the following new features:

Support for ServiceNow versions Kingston and London
Added the Configuration Management Database (CMDB) input as a default data input

Ansif
March 17, 2019

Hi, @Ansif -- This add-on does not support London because the add-on hasn't yet been tested with this SNOW version. Glad to hear it's working for you, anyway!

Jbalik splunk, Splunker
March 12, 2019

Vendor products "London" version not mentioned but in new feature London version supported.

Ansif
March 12, 2019

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters