Skip to main content
Threat Intelligence Security Center for Splunk app icon

Threat Intelligence Security Center for Splunk

The Threat Intelligence Security Center for Splunk with the ServiceNow integration provides an efficient way to enrich security operations by automating the retrieval, storage, and analysis of observables. Users can configure the interval at which they want to pull observables from the connected ServiceNow instance. This interval determines how frequently the system will make requests to ServiceNow to retrieve the observables data. Users can define and apply filters to specify which observables they want to pull from the ServiceNow instance. Once the observables are pulled from ServiceNow, they are stored in Splunk’s KV Store (Key-Value Store) and users can write correlation rules over the set of observables which were pulled in.Built by ServiceNow SecOps Applications
splunk product badge

Default Version 1.4.0

May 27, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3

Rating
0
(0)

Log in to rate this app

Support
Developer Supported

The Threat Intelligence Security Center for Splunk with the ServiceNow integration provides an efficient way to enrich security operations by automating the retrieval, storage, and analysis of observables. Users can configure the interval at which they want to pull observables from the connected ServiceNow instance. This interval determines how frequently the system will make requests to ServiceNow to retrieve the observables data. Users can define and apply filters to specify which observables they want to pull from the ServiceNow instance. Once the observables are pulled from ServiceNow, they are stored in Splunk’s KV Store (Key-Value Store) and users can write correlation rules over the set of observables which were pulled in.