Hi community!
I'm using Splunk Entreprise to create dashboards with my client's ServiceNow incident information.
1. My company ***only look at tickets from assignment_group A***.
2. So, I have a ***ticket X*** that belongs to ***assignment_group A*** with ***Status "New"***.
3. However, ***this ticket changed to assignment_group B*** and is no longer serviced by my company. **This will result in a second ServiceNow extraction, that ticket will not appear**.
So, I need to create a logic so that ***when this happens, Splunk changes the Status of ticket X to "Reassigned"***.
Does anyone know how to do this?
Thanks!
↧