Skip to content
This repository was archived by the owner on Sep 2, 2025. It is now read-only.

Commit 9c74308

Browse files
aaron suggestions
1 parent 6d975d7 commit 9c74308

File tree

1 file changed

+41
-36
lines changed

1 file changed

+41
-36
lines changed

admin/notif-services/servicenow.rst

Lines changed: 41 additions & 36 deletions
Original file line numberDiff line numberDiff line change
@@ -9,29 +9,52 @@ Send alert notifications to ServiceNow using Splunk Observability Cloud
99

1010
You can configure Splunk Observability Cloud to automatically send alert notifications to ServiceNow when a detector alert condition is met and when the alert clears.
1111

12-
.. note:: This configuration guide doesn't cover every type of integration you can create in Splunk Observability Cloud, and your configuration may vary from the examples shown here.
13-
1412
To send Splunk Observability Cloud alert notifications to ServiceNow, complete the following configuration tasks:
1513

1614
* :ref:`servicenow1`
1715

18-
You must be a ServiceNow administrator to complete this task.
19-
2016
* :ref:`servicenow2`
2117

22-
You must be a Splunk Observability Cloud administrator to complete this task.
18+
You must be a ServiceNow administrator to complete this task.
2319

2420
* :ref:`servicenow3`
2521

22+
You must be a Splunk Observability Cloud administrator to complete this task.
23+
24+
* :ref:`servicenow4`
2625

27-
.. _servicenow1:
26+
.. _servicenow1:
2827

29-
Step 1: Create a ServiceNow user for your Splunk Observability Cloud integration
28+
Step 1: Choose the type of ServiceNow issue for your integration
29+
=================================================================================
30+
31+
Before you set up the integration, choose a ServiceNow issue type from the following table:
32+
33+
.. list-table::
34+
:header-rows: 1
35+
:width: 100
36+
37+
* - Issue type
38+
- Role needed
39+
* - Problem
40+
- ``user_admin``, ``itil``
41+
* - Incident
42+
- ``user_admin``, ``itil``
43+
* - Event
44+
- None
45+
46+
Make note of the role that corresponds to your issue type before proceeding with :ref:`servicenow2`.
47+
48+
.. note:: The ``user_admin`` role is used to verify that ServiceNow has successfully created a Problem or Incident. The ``itil`` role is used to create Problems and Incidents when alerts are sent.
49+
50+
.. _servicenow2:
51+
52+
Step 2: Create a ServiceNow user for your Splunk Observability Cloud integration
3053
=================================================================================
3154

3255
In this step, you create a ServiceNow user that you can use to receive alert notifications from Splunk Observability Cloud. You must be a ServiceNow administrator to complete this task.
3356

34-
If you have an existing ServiceNow user that you want to use to receive alert notifications, the user has the :strong:`web_service_admin` and :strong:`itil` roles assigned, and you know the user ID and password, you can skip to :ref:`servicenow2`.
57+
If you have an existing ServiceNow user that you want to use to receive alert notifications, the user has the roles assigned that correspond to your issue type, and you know the user ID and password, you can skip to :ref:`servicenow2`.
3558

3659
To set up a ServiceNow user for your Splunk Observability Cloud integration:
3760

@@ -43,24 +66,22 @@ To set up a ServiceNow user for your Splunk Observability Cloud integration:
4366

4467
#. Enter :strong:`User ID`, :strong:`First name`, and :strong:`Last name` values that clearly communicate that the user is associated with Splunk Observability Cloud notifications. Make note of the :strong:`User ID` value for use in subsequent steps.
4568

46-
#. Enter a :strong:`Password` value. Make note of this value for use in :ref:`servicenow2`.
69+
#. Enter a :strong:`Password` value. Make note of this value for use in :ref:`servicenow3`.
4770

4871
#. Select the :strong:`Active` check box.
4972

5073
#. Select :strong:`Submit`.
5174

5275
#. Find your new user by either searching for the user ID or doing a reverse chronological sort on the :strong:`Created` column. Select the user ID to open the user information window. Scroll down and select the :strong:`Roles` tab. Select :strong:`Edit`.
5376

54-
#. In the :strong:`Collection` search field, enter :strong:`web_service_admin`. Select the :strong:`web_service_admin` role and select :strong:`>` to move it the :strong:`Roles List` panel.
77+
#. In the :strong:`Collection` search field, enter the roles for the issue type you chose in :ref:`servicenow1`, for example, ``user_admin``. Select the role and select :strong:`>` to move it the :strong:`Roles List` panel.
5578

56-
#. Similarly, in the :strong:`Collection` search field, search for :strong:`itil`. Select the :strong:`itil` role and select :strong:`>` to move it the :strong:`Roles List` panel.
79+
#. Select :strong:`Save`. The new roles display on the :strong:`Roles` tab for the user.
5780

58-
#. Select :strong:`Save`. :strong:`web_service_admin` and :strong:`itil` display on the :strong:`Roles` tab for the user, possibly along with other additional roles.
5981

82+
.. _servicenow3:
6083

61-
.. _servicenow2:
62-
63-
Step 2: Create a ServiceNow integration in Splunk Observability Cloud
84+
Step 3: Create a ServiceNow integration in Splunk Observability Cloud
6485
=================================================================================
6586

6687
You must be a Splunk Observability Cloud administrator to complete this task.
@@ -81,40 +102,24 @@ To create a ServiceNow integration in Splunk Observability Cloud:
81102
#. Select :strong:`New Integration` to display the configuration options.
82103

83104
#. By default, the name of the integration is :strong:`ServiceNow`. Give your integration a unique and descriptive name. For information about the downstream use of this name, see :new-page-ref:`About naming your integrations <naming-note>`.
84-
#. In the :strong:`Username` field, enter the user ID from ServiceNow in :ref:`servicenow1`.
85-
#. In the :strong:`Password` field, enter the password from ServiceNow in :ref:`servicenow1`.
105+
#. In the :strong:`Username` field, enter the user ID from ServiceNow in :ref:`servicenow2`.
106+
#. In the :strong:`Password` field, enter the password from ServiceNow in :ref:`servicenow2`.
86107
#. In the :strong:`Instance Name` field, enter your ServiceName instance name. For example, the instance name must use the format ``example.service-now.com``. Do not include a leading ``https://`` or a trailing ``/``. Additionally, you cannot use local ServiceNow instances.
87108

88109
To troubleshoot potential blind server-side request forgeries (SSRF), Splunk Observability Cloud has included ``\*.service-now.com`` on an allow list. As a result, if you enter a domain name that is rejected by Splunk Observability Cloud, contact :ref:`support` to update the allow list of domain names.
89110

90111
#. Select :strong:`Incident`, :strong:`Problem`, or :strong:`Event` to indicate the issue type you want the integration to create in ServiceNow. If necessary, you can create a second integration using the other issue type. This lets you create an incident issue for one detector rule and a problem issue for another detector rule. The following table shows the roles required to create each issue type:
91112

92-
.. list-table::
93-
:header-rows: 1
94-
:width: 100
95-
96-
* - Issue type
97-
- Role needed
98-
* - Problem
99-
- ``user_admin``, ``itil``
100-
* - Incident
101-
- ``user_admin``, ``itil``
102-
* - Event
103-
- None
104-
105113
#. :strong:`Save`.
106114

107115
#. If Splunk Observability Cloud can validate the ServiceNow username, password, and instance name combination, a :strong:`Validated!` success message displays. If an error displays instead, make sure that the values you entered match the values in ServiceNow.
108116

109117

110-
.. _servicenow3:
118+
.. _servicenow4:
111119

112-
Step 3: Add a ServiceNow integration as a detector alert recipient in Splunk Observability Cloud
120+
Step 4: Add a ServiceNow integration as a detector alert recipient in Splunk Observability Cloud
113121
=================================================================================================
114122

115-
..
116-
once the detector docs are migrated - this step may be covered in those docs and can be removed from these docs. below link to :ref:`detectors` and :ref:`receiving-notifications` instead once docs are migrated
117-
118123
To add a ServiceNow integration as a detector alert recipient in Splunk Observability Cloud:
119124

120125
#. Create or edit a detector that you want to configure to send alert notifications using your ServiceNow integration.
@@ -123,7 +128,7 @@ To add a ServiceNow integration as a detector alert recipient in Splunk Observab
123128

124129
#. In the :strong:`Alert recipients` step, select :strong:`Add Recipient`.
125130

126-
#. Select :strong:`ServiceNow` and then select the name of the ServiceNow integration you want to use to send alert notifications. This is the integration name you created in :ref:`servicenow2`.
131+
#. Select :strong:`ServiceNow` and then select the name of the ServiceNow integration you want to use to send alert notifications. This is the integration name you created in :ref:`servicenow3`.
127132

128133
#. Activate and save the detector.
129134

0 commit comments

Comments
 (0)