logo

NJP

Splunk ES Integration for Security Operations

Splunk ES Integration for Security Operations

by Service-now.com

Create security response incidents automatically from Splunk Enterprise Security Notable Events.

0 installs 0 reviews v12.5.1 Scoped Application Free (integration tables[12] not counted) 12 tables
Developer Instance Sub-Production

Install Trend

First tracked: 2024-10-30 Latest: 2026-09-09 (0 installs)
View Install Data
Date Install Count Change
2026-09-09 0 -
134 days of no change
2026-04-27 150 -150
165 days of no change
2025-11-12 149 +1
12 days of no change
2025-10-30 148 +1
7 days of no change
2025-10-22 147 +1
32 days of no change
2025-09-19 146 +1
18 days of no change
2025-08-31 145 +1
47 days of no change
2025-07-14 144 +1
20 days of no change
2025-06-23 143 +1
55 days of no change
2025-04-28 142 +1
3 days of no change
2025-04-24 141 +1
15 days of no change
2025-04-08 140 +1
6 days of no change
2025-04-01 139 +1
17 days of no change
2025-03-14 138 +1
8 days of no change
2025-03-05 137 +1
2025-03-04 136 +1
13 days of no change
2025-02-18 135 +1
22 days of no change
2025-01-26 134 +1
8 days of no change
2025-01-17 133 +1
78 days of no change
2024-10-30 130 +3

About

The Splunk ES Event Ingestion integration for Security Operations allows security operations center (SOC) analysts to generate Now Platform® Security Incident Response (SIR) incidents automatically when certain configured Splunk ES Notable Events are triggered. Analysts can also manually forward selected events on-demand from the Splunk ES console. Analysts respond to the security incidents that are created with workflows in the Now Platform that automate incident response activities and remediation.

Key Features

This integration includes the following key features:

- Create multiple alert ingestion profiles to create SIR security incidents for specific types of threats, such as phishing and malware.
- Create multiple event profiles for on-demand event forwarding from your Splunk ES console to create SIR security incidents
- Drag-and-drop mapping of Splunk ES notable events and event field values to associated SIR security incident fields.
- A SIR security incident layout preview based on sample alerts or events to validate profile configuration.
- Ingest historical alerts and ongoing or future alerts at configurable intervals.
- Aggregate events or alerts to existing SIR security incidents based on matching field values to avoid duplicate security incidents.

Version History (12)
v12.5.1 2026-06-16 16:43:08
Fixed: Refactored the UI macros and backend logic to correctly distinguish between sample types, removed unreachable dead code, and fixed correlat...
v12.5.0 2026-04-09 15:24:49
New : Handling missing CMDB CIs gracefully by attaching them as Unmatched CI. New correlation rules in Splunk ES  automatically imported peri...
v12.4.0 2025-12-11 13:43:03
New : Upgraded all dictionary-level read-only fields to Strict Read-Only to enhance security and prevent unauthorized changes.This update ensures ...
v12.3.0 2025-11-06 14:56:42
Fixed:- New splunk upgrade failing xml parsing and blocks SIR creation. Not able to edit existing Field translations.
v12.2.2 2025-10-16 15:10:44
Fixed:- Token restoration bug in SplunkESEventIngestionQueryAbstract._buildInputValue corrupts literal values that look like $…$ (e.g., $DOVERIE01...
v12.2.1 2025-09-10 12:07:02
Fixed:  Splunk ES update multiple is working in iterative mode. We have added fix to clean up the stale records in internal tables.
v12.2.0 2025-07-31 15:34:37
New:- Enabling users with "sn_si.ingestion_profile_admin" role to manage ingestion profiles on Splunk ES Integration. Update Field values for nota...
v12.1.10 2025-07-10 14:56:56
Fixed: Defect: The Splunk Enterprise Security (ES) process responsible for sending events to the Security Incident Response (SIR) job was causing ...
v12.1.9 2025-06-06 01:20:28
Fixed: Defect: The Splunk ES process for sending events to the Security Incident Response (SIR) job was causing memory contention on nodes, leadin...
v12.1.6 2025-05-01 18:57:04
Fixed: The following defects as part of this release: Supports adding multiple affected users during Splunk Enterprise event ingestion for Securit...

+ 2 more versions

ID: b603f357e556f300a36baaf2972ed766 · Published: Jun 2026 · Updated: Sep 09, 2026