logo

NJP

Splunk Enterprise Event Ingestion for Security Operations

Splunk Enterprise Event Ingestion for Security Operations

by Service-now.com

Create security response incidents automatically from Splunk Enterprise Events and Alerts.

0 installs 0 reviews v11.6.4 Scoped Application Free (integration tables[14] not counted) 14 tables
Developer Instance Sub-Production

Install Trend

First tracked: 2024-10-30 Latest: 2026-09-09 (0 installs)
View Install Data
Date Install Count Change
2026-09-09 0 -
134 days of no change
2026-04-27 107 -107
144 days of no change
2025-12-03 106 +1
20 days of no change
2025-11-12 105 +1
21 days of no change
2025-10-21 104 +1
22 days of no change
2025-09-28 103 +1
18 days of no change
2025-09-09 102 +1
33 days of no change
2025-08-06 101 +1
16 days of no change
2025-07-20 100 +1
2 days of no change
2025-07-17 99 +1
23 days of no change
2025-06-23 97 +2
47 days of no change
2025-05-06 96 +1
11 days of no change
2025-04-24 95 +1
87 days of no change
2025-01-26 94 +1
87 days of no change
2024-10-30 91 +3

About

The Splunk Enterprise Event Ingestion Integration for Security Operations allows security operations center (SOC) analysts to automatically generate Now Platform® Security Incident Response (SIR) incidents when certain configured Splunk Enterprise alerts are triggered. Analysts can also manually forward selected events on-demand from the Splunk console. Analysts respond to the security incidents created with workflows in the Now Platform that automate incident response activities and remediation.

Key Features

This integration includes the following key features:

- Create multiple alert ingestion profiles to create SIR security incidents for specific threats such as phishing and malware.
- Create multiple event profiles for on-demand event forwarding from your Splunk console to create SIR security incidents
- Drag-and-drop the mapping of Splunk alert and event field values to the associated SIR security incident fields.
- A preview of the SIR security incident layout based on sample alerts or events to validate profile configuration.
- Ingest historical alerts and ongoing and future alerts on configurable intervals.
- Aggregate events or alerts to existing SIR security incidents based on matching field values to avoid duplicate security incidents.

Version History (8)
v11.6.4 2026-06-16 16:43:45
Fixed :  Data ingestion issue caused by Splunk indexing delay.
v11.6.3 2026-05-05 14:58:40
Fixed :  Cobalt Raven Non-Glide Query ACLs Directive:        Resolved issues related to ACL directives for non-Glide...
v11.6.2 2026-03-12 16:13:45
New : Incorporated strategies to present data without relying on CMDB or identity tables in the integration.
v11.5.1 2025-12-11 13:41:54
New : Upgraded all dictionary-level read-only fields to Strict Read-Only to enhance security and prevent unauthorized changes.This update ensures ...
v11.4.1 2025-07-31 15:36:45
New:- Enabling users with "sn_si.ingestion_profile_admin" role to manage ingestion profiles on Splunk V2 Integration Fixed:- Handled node restar...
v11.3.4 2025-06-06 01:20:35
Fixed: When multiple values are going in the affected users or configurations items from splunk, an error alert message pop up with the message: i...
v11.3.3 2025-04-03 13:29:51
Fixed: Issue related to the configuration item mapping.
v11.3.1 2024-11-07 15:19:45
Changed: Changed the Search API to v2 version. Fixed: An intermittent 404 error during ingestion is happened. Null pointer check was missing for...
ID: da9efe66733213004b24e93a4cf6a709 · Published: Jun 2026 · Updated: Sep 09, 2026