I just installed the Splunk Add-on for ServiceNow 2.7.0, and the Splunk App for ServiceNow 4.0.0 on a test bed.
We're behind a proxy. I configured the credentials in the TA, and set up the proxy settings.
I went to configure the inputs from the Splunk App for ServiceNow applications, and it fails with credentials failures; I *think* it's because the Splunk App for ServiceNow does not know about the proxy when it's verifying credentials. In any case, I decided to just configure the credentials directly in the TA and enable them there.
The inputs for the TA are all set up to go to index 'main'. If I had been able to use the Splunk App for ServiceNow to set up the inputs, would it be wanting to plop the data down in indexes created by that app?
↧