Manual search commands
-
- UpdatedJan 30, 2025
- 2 minutes to read
- Yokohama
- ServiceNow Security Operations add-on for Splunk
Manual search commands are entered from any Search window. You can create a security incident or event. After the command, there are pairs of field names and values used to create the desired record.
Security event
The security event command, snsecevent, creates an event in ServiceNow with the Security classification.
These events can be reviewed on their own, or alert rules within ServiceNow or manual actions can turn an event or collection of events into a security incident.
Security incident
The Security Incident command, snsecincident, creates a Security Incident in your ServiceNow instance.
There are many possible useful columns – anything in the Security Incident transform map can be used. If new columns are added to the security incident, they too are used, as long as they are in the transform map. Some useful columns: location, priority, assignment_group, assigned_to, affected_user, attack_vector, and watch_list.