The Splunk Add-on for ServiceNow enables bi-directional integration between Splunk and ServiceNow platforms. The add-on collects data from ServiceNow tables including incidents, problems, change requests, event management events, CMDB configuration items, system events, audit logs, and user/group data. It provides field extractions that normalize ServiceNow data to the Common Information Model (CIM) for the Authentication and Change domains, enabling correlation with other enterprise data sources. The add-on includes custom search commands for querying ServiceNow records directly from Splunk, alert actions for creating and updating ServiceNow incidents and events from Splunk searches, and workflow actions for pivoting from Splunk events to corresponding ServiceNow records. Lookup tables are automatically populated with ServiceNow reference data such as user lists, location hierarchies, and CMDB configuration item relationships. The add-on supports both OAuth 2.0 and Basic authentication methods for connecting to ServiceNow instances.