Import a maintenance window from ServiceNow
Import maintenance schedules applied to ServiceNow objects into Splunk IT Service Intelligence (ITSI).
Import a maintenance schedule from ServiceNow
Use the out-of-the-box ServiceNow Outage integration to periodically import new or updated ServiceNow outage records, and create maintenance windows in ITSI.
- You must have itoa_admin or itoa_team_admin permissions.
- Install the Splunk Add-on for ServiceNow. For more information, see Install and configure the Splunk Add-on for ServiceNow.
-
Confirm that the external maintenance windows setting is on. Select Configuration then Advanced Configuration and enable the External CI maintenance windows setting.
-
Create and activate the following data inputs in the add-on to ensure your data gets ingested:
-
cmdb_ci: Required to populate configuration items
-
cmdb_ci_outage: Planned outage records
-
(Optional) cmdb_rel_ci
-
- In Splunk ITSI, navigate to Configuration then Additional Configuration then Maintenance Windows. Alternatively, from the Data Integrations page, select the Integrations library tab, and select Maintenance/Outages.
- If creating an import, create a recurring import with the data source ServiceNow. Alternatively, from the Integrations library, select the ServiceNow Outage.
- Review and edit the default field mappings to ensure they match your environment. The mappings include:
- Title: Maintenance window name
- Start Time: Maps to the maintenance window start time
- End Time: Maps to the maintenance window end time
- CI ID: Maps to the specific configuration item
sys_idreference. ServiceNow CIsys_idmust match an external CI in ITSI - Outage ID: Unique outage record ID used to update existing imported maintenance windows
- Set the Schedule to determine how frequently ITSI should query ServiceNow for new outages (for example, every 15 minutes).
- Set a time range for the search to set how far back each search runs (the default is the last 30 minutes).
- Validate the search to confirm outage data is available.
- Select Save to enable the integration. Your new integration is added to the ServiceNow Outage Integration page, and generates a scheduled saved search.
When maintenance windows are ingested into ITSI, an alert is generated whenever a CI enters a maintenance window, and another alert is generated when the maintenance window ends. These maintenance window alerts can also be correlated into an episode, allowing you to identify whether any CI associated with the episode was under maintenance.
Additionally, when configuring a NEAP, you can also enable action suppression to prevent action rules from running while any CI associated with an episode is in a maintenance window. To view episodes where actions were suppressed, go to Maintenance Windows, select a maintenance window, and open the Impacted Episodes tab.
View the imported planned outages on the Maintenance Windows page in ITSI, which are tagged with the target type External CI. To view the planned outages, select Configuration then Additional Configuration then Maintenance Windows.