Set up or change the instance where incidents or events are created To set up or change the ServiceNow instance where new security incidents and security events are created, use the Setup action in the application list. Open Splunk. Click either the Apps gear icon, or the Manage Apps shortcut menu item. In the list of applications, click the Set up action for the ServiceNow Security Operations Integration. Provide the ServiceNow URL, user name, and password. The user name and password are for the integration user created in ServiceNow. Click Save.