Splunk® App for ServiceNow

User Guide

Download manual as PDF

Download topic as PDF

Get your data for the Splunk App for ServiceNow

Work with the dashboards

Use the dashboards provided by the Splunk App for ServiceNow to access and analyze your data.

See "Overview of the dashboards in the Splunk App for ServiceNow" for an introduction to the dashboards and some tips for troubleshooting if you do not see your data.

Run the saved searches

The Splunk Add-on for ServiceNow, a dependency of the Splunk App for ServiceNow, provides a set of saved searches. These searches, enabled automatically when your admin configures the app, make the data on your dashboards easier to consume by replacing IDs with more readable labels.

The saved searches run once an hour, on the hour. You can also run them immediately from Settings > Searches, reports and alerts. Change the app context to Splunk Add-on for ServiceNow to see the relevant saved searches.

Work with push integration

The Auto-Created Incidents dashboard will only display data if you use the push integration features available with the Splunk App for ServiceNow.

See "Push integration with the Splunk App for ServiceNow" for information about the commands, alert actions, and scripts that you can use to create incidents and events in ServiceNow from the Splunk platform.


As with any data source, you can search the raw data in the Splunk platform. For a full list of source types to use in your searches, see "Data the Splunk App for ServiceNow collects" in the Installation and Configuration manual.

Log in and get started with the Splunk App for ServiceNow
Push integration with the Splunk App for ServiceNow

This documentation applies to the following versions of Splunk® App for ServiceNow: 4.0.0, 4.0.1, 4.0.2, 4.0.3

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters