Splunk® Supported Add-ons

Splunk Add-on for ServiceNow

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

Release notes for the Splunk Add-on for ServiceNow

Version 7.8.0 of the Splunk Add-on for ServiceNow was released on April 30, 2024.

Compatibility

Version 7.8.0 of the Splunk Add-on for ServiceNow is compatible with the following software, CIM versions, and platforms:

Splunk platform versions 9.0.x, 9.1.x, 9.2.x
CIM 5.1.0
Supported OS for data collection Platform Independent
Vendor products ServiceNow Quebec, Rome, San Diego, Tokyo, Utah, Vancouver, and Washington DC

Splunk has reviewed and updated the field aliases in this add-on for compatibility with the new field alias behavior change available from Splunk v7.3.4 and above.

For more information about the field alias configuration change, refer to the Splunk Enterprise Release Notes.

New features

Version 7.8.0 of the Splunk Add-on for ServiceNow includes the following new features:

  • Added support for ServiceNow Washington DC.
  • Added support for ipv6 addresses.
  • Added a unique invocation ID for every invocation in the logs for alert action and custom commands.
  • Enhanced data collection mechanism to ingest a record without a time field.
  • Improved data collection mechanism by using sys_id instead of offset for record updates during ongoing data collection. Please note that intermediate updates of a record can still be missed if there are multiple updates on a record between the input intervals. The latest state of the record will be fetched in the next invocation of the input according to its interval.


Version 6.3.0 and above of the Splunk Add-on for ServiceNow deprecates support for events fetched through the display_value = false (extractions and Common Information Model (CIM) mappings) setting. The best practice is to set display_value to all in your deployment going forward and to revert the extractions in your props.conf accordingly. For more information, see the Edit the display values for the ServiceNow API section of the Upgrade topic in this manual.

From the ServiceNow add-on release 7.2.1 onward, we have removed the support of HTTP_NO_TUNNEL and SOCKS4 proxy. We recommend using an HTTP or SOCKS5 proxy instead.

Fixed issues

Version 7.8.0 of the Splunk Add-on for ServiceNow has the following, if any, fixed issues. If no issues appear below, no issues have yet been reported:

Known issues

Version 7.8.0 of the Splunk Add-on for ServiceNow has the following known issues. If no issues appear below, no issues have yet been reported:

Third-party software attributions

Some of the components included in this add-on are licensed under free or open source licenses. We wish to thank the contributors to those projects.

A complete listing of third-party software information for this add-on is available as a document file for download:
Splunk Add-on for ServiceNow third-party software credits.

Last modified on 30 April, 2024
PREVIOUS
Source types for the Splunk Add-on for ServiceNow
  NEXT
Release history for the Splunk Add-on for ServiceNow

This documentation applies to the following versions of Splunk® Supported Add-ons: released, released


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters