Copy Splunk Enterprise Security profiles from one instance to another using export/import functionality
-
- UpdatedJan 30, 2025
- 3 minutes to read
- Yokohama
- Splunk Enterprise Security Event Ingestion Integration
Copy Splunk Enterprise Security profiles from one instance to another using export/import functionality
You can export and import Splunk Enterprise Security profiles settings from one ServiceNow AI Platform instance to a different ServiceNow AI Platform instance.
Before you begin
The settings you can export and import include profile name, correlation rules, mappings, filters, aggregation criteria, field translations, fetched sample data, scheduling, and configuration tile source information.
Role required: sn_si.ingestion_profile_admin
About this task
This functionality allows the security administrator to copy profiles that have been tested and verified on one ServiceNow AI Platform instance, for example on non-production, to another ServiceNow AI Platform instance, for example production, without the need to redo all configuration settings. The settings that are exported and imported include profile name, correlation rules, mappings, filters, aggregation criteria, field translations, fetched sample data, scheduling, and configuration tile source information.
Procedure