I am using "Splunk app for Servicenow" & "Splunk add-on for ServiceNow" which is integrated with ServiceNow.
I want to extract only those incidents in Splunk indexer (snow) from ServiceNow where "assignment_group" = "XYZ" or "ABC"
Currently it is extracting million of events in Splunk from ServiceNow Incidents.
↧