To enable the sharing of ITSM data from your ServiceNow instance to your Splunk instance, you will need to create a ServiceNow bulk share and/or a ServiceNow dynamic share. A ServiceNow bulk share is a one-time transfer of data from your ServiceNow instance. A ServiceNow dynamic share allows for real time sharing of ServiceNow records as they are created, updated, and deleted. Creating a bulk share and/or dynamic share will share out your ServiceNow data immediately as well as share out subsequent data that is collected as ServiceNow records are created, updated, and deleted.

(info) NOTE: Like other DataSync targets, ServiceNow fields that have display values will save with the sys_id as the field's value in Splunk. To also share the display values, turn on the DataSync display value property.

Prerequisites


(warning) You will first need to install the Perspectium Core update set. You can request a download link for this update set by contacting Perspectium Support.

(warning) You will also need to create a ServiceNow shared queue that points to your Splunk instance. This queue should have been created by Perspectium Support upon initial configuration of your ServiceNow instance.


Procedure

To create a bulk/dynamic share for your ServiceNow-to-Splunk integration, follow these steps:


To create a bulk share, navigate to Perspectium DataSync > Bulk Share or simply type Bulk Share in the Filter Navigator on the upper left-hand side of the screen.

Click the New button next to Bulk Shares. In the resulting form's Cipher dropdown, select Base64 Encode Only. Then, follow the remaining steps to create a ServiceNow bulk share for DataSync for ServiceNow. 

OR

To create a dynamic share, navigate to Perspectium DataSync > Dynamic Share or simply type Dynamic Share in the Filter Navigator on the upper left-hand side of the screen.

Click the New button next to DataSync Configurations. In the resulting form's Cipher dropdown, select Base64 Encode Only. Then, follow the remaining steps to create a ServiceNow dynamic share for DataSync for ServiceNow. 

Next steps


Open your Splunk HTTP Event Collector port to the Perspectium Integration Mesh