# ServiceNow integration with Elasticsearch

**URL:** https://discuss.elastic.co/t/servicenow-integration-with-elasticsearch/218095
**Category:** Elasticsearch
**Created:** [February 6, 2020, 6:30am UTC](https://discuss.elastic.co/t/servicenow-integration-with-elasticsearch/218095 "2020-02-06T06:30:05Z")
**Posts on this page:** 11
**Page:** 1

<div class="post-metadata">

### Author: ![tahseen\_fatima](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tahseen_fatima/32/67789_2.png) [@tahseen\_fatima](https://discuss.elastic.co/u/tahseen_fatima)
#### Post date: [February 6, 2020, 6:30am UTC](https://discuss.elastic.co/t/servicenow-integration-with-elasticsearch/218095/1 "2020-02-06T06:30:05Z")

</div>

Hi,

I have a setup of ELK Stack 7.5.1 to visualize/analyse different kind of logs in our environment. Now, I have a serviceNow of tool where we raise ticket.  
I want to integrate serviceNow with elasticsearch is there any direct integration available?  
Please help.

Thanks,  
Regards,  
Tahseen

---

<div class="post-metadata">

### Author: ![ropc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ropc/32/47022_2.png) [@ropc](https://discuss.elastic.co/u/ropc)
#### Post date: [February 6, 2020, 7:40am UTC](https://discuss.elastic.co/t/servicenow-integration-with-elasticsearch/218095/2 "2020-02-06T07:40:16Z")

</div>

Hi @tahseen_fatima - Could you tell us more about your use case and what you would expect as part of the integration with ServiceNow?

---

<div class="post-metadata">

### Author: ![tahseen\_fatima](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tahseen_fatima/32/67789_2.png) [@tahseen\_fatima](https://discuss.elastic.co/u/tahseen_fatima)
#### Post date: [February 6, 2020, 10:56am UTC](https://discuss.elastic.co/t/servicenow-integration-with-elasticsearch/218095/3 "2020-02-06T10:56:28Z")

</div>

HI,  
Firstly thank you for the reply.

We are using serviceNow Madrid ticketing tool,  
my use case is: whoever raised a new ticket in serviceNow that ticket should automatically ingest it to elasticsearch.  
After that we can able to analysize.

Thanks,  
Regards,  
Tahseen

---

<div class="post-metadata">

### Author: ![ropc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ropc/32/47022_2.png) [@ropc](https://discuss.elastic.co/u/ropc)
#### Post date: [February 6, 2020, 12:46pm UTC](https://discuss.elastic.co/t/servicenow-integration-with-elasticsearch/218095/4 "2020-02-06T12:46:20Z")

</div>

@tahseen_fatima Thank you for the information provided.

There is no out-of-the-box integration between Elasticsearch and ServiceNow.

I am not an expert with ServiceNow, but these ideas below could be worth exploring:

- Use Logstash and the [http\_poller input plugin](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-http_poller.html) to retrieve data from the incident table in ServiceNow.
- Looking at the documentation in ServiceNow, it might be possible to define a business rule when an event is triggered and use the [outbound REST web service](https://docs.servicenow.com/bundle/madrid-application-development/page/integrate/outbound-rest/concept/c_OutboundRESTWebService.html) (e.g. calling Logstash / Elasticsearch APIs to ingest documents).

I hope that helps.

---

<div class="post-metadata">

### Author: ![tahseen\_fatima](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tahseen_fatima/32/67789_2.png) [@tahseen\_fatima](https://discuss.elastic.co/u/tahseen_fatima)
#### Post date: [February 7, 2020, 6:49am UTC](https://discuss.elastic.co/t/servicenow-integration-with-elasticsearch/218095/5 "2020-02-07T06:49:33Z")

</div>

Hi,  
Thank you for the reply.

This is my logstash config file:

```
input {
  http_poller {
    urls => {
      url => "https://dev68751.service-now.com"
        }
    request_timeout => 60
    #proxy => { host => "0.0.0.0" port => "443" scheme => "http"}
    schedule => { cron => "* * * * * UTC"}
    metadata_target => "http_poller_metadata"
    codec => "json"
    user => "admin"
    password => " ***** @"
  }
}
output {
  stdout {
    codec => rubydebug
  }
}

```

The output I am getting.

```
.base');\nvar $targets = angular.element('*[concourse-compilation-target]');\nvar bootstrapModule = angular.module('appBootstrap', window.NOW.ngLoadModules);\nangular.bootstrap(document.documentElement, [bootstrapModule.name]);\nscheduleCompilation($targets);\n}\nangular.element(document).ready(function() {\nsetTimeout(bootstrap)\n});\n})(angular, window);\n;\n</script></body></html>",
                    "tags" => [
        [0] "_jsonparsefailure"
    ],
    "http_poller_metadata" => {
           "times_retried" => 0,
                    "host" => "tahseen",
        "response_headers" => {
                              "expires" => "0",
                                 "date" => "Fri, 07 Feb 2020 06:40:51 GMT",
                               "pragma" => "no-store,no-cache",
                      "x-frame-options" => "SAMEORIGIN",
                         "content-type" => "text/html;charset=UTF-8",
                       "x-is-logged-in" => "false",
            "strict-transport-security" => "max-age=63072000; includeSubDomains",
                     "x-transaction-id" => "f0602b7ddb76",
                               "server" => "ServiceNow",
                      "referrer-policy" => "same-origin",
                        "cache-control" => "no-cache,no-store,must-revalidate,max-age=-1",
                    "transfer-encoding" => "chunked",
                           "set-cookie" => [
                [0] "JSESSIONID=817CE4D2BCCD20095554E7EB311FA0E8; Path=/; HttpOnly;Secure",
                [1] "glide_user=; Max-Age=0; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/; HttpOnly;Secure",
                [2] "glide_user_session=; Max-Age=0; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/; HttpOnly;Secure",
                [3] "glide_user_route=glide.d0049332062fb78bdaadecdaf9983d3c; Max-Age=2147483647; Expires=Wed, 25-Feb-2088 09:54:58 GMT; Path=/; HttpOnly;Secure",
                [4] "BIGipServerpool_dev68751=192960522.64064.0000; path=/; Httponly; Secure"
            ]
        },
        "response_message" => "OK",
         "runtime_seconds" => 2.023368,
                    "name" => "url",
                 "request" => {
               "url" => "https://dev68751.service-now.com",
            "method" => "get"
        },
                    "code" => 200
    }
}

```

Why it is giving "\_jsonparsefailure"

Kindly help.

Thanks,  
Tahseen

---

<div class="post-metadata">

### Author: ![ropc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ropc/32/47022_2.png) [@ropc](https://discuss.elastic.co/u/ropc)
#### Post date: [February 7, 2020, 7:53am UTC](https://discuss.elastic.co/t/servicenow-integration-with-elasticsearch/218095/6 "2020-02-07T07:53:32Z")

</div>

@tahseen_fatima - the `url` is not correct - this is not a valid ServiceNow REST API endpoint.

You should check the [REST API reference](https://docs.servicenow.com/bundle/madrid-application-development/page/build/applications/concept/api-rest.html) from ServiceNow and choose which REST API endpoint you wish to use.

---

<div class="post-metadata">

### Author: ![tahseen\_fatima](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tahseen_fatima/32/67789_2.png) [@tahseen\_fatima](https://discuss.elastic.co/u/tahseen_fatima)
#### Post date: [February 7, 2020, 8:05am UTC](https://discuss.elastic.co/t/servicenow-integration-with-elasticsearch/218095/7 "2020-02-07T08:05:59Z")

</div>

Hi,

Now I am giving this url  
`url => "https://dev***.service-now.com//api/now/table/incident?sysparm_query=number=INC0000601"`

No I am getting the following output.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/8/58fbb7b9be6e84752b2bb4cd0290d410582998ec.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/c/4c051ec13fd426f5ce4d1f72aae787c984e98671.png)

Now I am getting the proper output.

But I want to ingest multiple incidents. Kindly refer the below image.

 ![Screenshot from 2020-02-07 13-33-56](https://us1.discourse-cdn.com/elastic/original/3X/e/4/e44c25c116808981b4f7623827d8b69deb7bff33.png)

Thanks,  
Tahseen

---

<div class="post-metadata">

### Author: ![ropc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ropc/32/47022_2.png) [@ropc](https://discuss.elastic.co/u/ropc)
#### Post date: [February 7, 2020, 8:23am UTC](https://discuss.elastic.co/t/servicenow-integration-with-elasticsearch/218095/8 "2020-02-07T08:23:15Z")

</div>

@tahseen_fatima - I am not an expert in ServiceNow API but from what I can see, the previous `url` is matching a specific incident number (i.e. `sysparm_query=number=INC0000601`). You would need to check which query parameters would return to you the list of desired documents.

---

<div class="post-metadata">

### Author: ![tahseen\_fatima](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tahseen_fatima/32/67789_2.png) [@tahseen\_fatima](https://discuss.elastic.co/u/tahseen_fatima)
#### Post date: [February 7, 2020, 10:01am UTC](https://discuss.elastic.co/t/servicenow-integration-with-elasticsearch/218095/9 "2020-02-07T10:01:54Z")

</div>

Okay!!  
Thanks for your help.

Tahseen.

---

<div class="post-metadata">

### Author: ![tahseen\_fatima](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tahseen_fatima/32/67789_2.png) [@tahseen\_fatima](https://discuss.elastic.co/u/tahseen_fatima)
#### Post date: [February 7, 2020, 10:31am UTC](https://discuss.elastic.co/t/servicenow-integration-with-elasticsearch/218095/10 "2020-02-07T10:31:34Z")

</div>

Hi,

Thanks for the help,  
I have solved the issue.

This is my new url.  
`url => "https://dev68751.service-now.com/api/now/table/incident?sysparm_display_value=false&sysparm_fields=number%2Cstate%2Cpriority&sysparm_limit=10"`

output:

 ![Screenshot from 2020-02-07 15-51-59](https://us1.discourse-cdn.com/elastic/original/3X/f/d/fdbc3e08e74008457de627aa569859b45c5170bc.png)

Now I am getting the full data.

Thanks,  
Tahseen

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 6, 2020, 10:31am UTC](https://discuss.elastic.co/t/servicenow-integration-with-elasticsearch/218095/11 "2020-03-06T10:31:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
