ServiceNow Incidents connector
This connector remains supported but will be deprecated in a future release. For new deployments, use the ServiceNow Tickets connector, which provides enhanced capabilities and ongoing feature development.
The ServiceNow Incidents connector provides a secure and configurable integration with ServiceNow Incident. It ingests historical incident data, streams new and updated tickets, and enriches analytics and insights. The connector includes out-of-the-box mappings to accelerate setup and ensure consistent data integration.
The ServiceNow Incidents connector enables Spark to continuously learn from escalated tickets. Refer to Managing Spark settings and data inputs documentation.
Configuring the Connector credentials
To allow Nexthink to retrieve incidents information from your ServiceNow instance, you need to set up a dedicated integration account in ServiceNow with the right level of access.
The Nexthink Incidents connector accesses ServiceNow incident data through the ServiceNow Table API.
Follow the steps below to configure the ServiceNow credentials used to fetch incidents:
Create a dedicated active ServiceNow user account for Nexthink integration in the ServiceNow Admin Console and enable it for API authentication.
Assign an existing read-only role or create a dedicated read-only role (for example,
x_nexthink_ticket_reader) for the Nexthink integration user in ServiceNow Roles administration.Configure ServiceNow table-level read Access Control Lists (ACLs) to allow the Nexthink read-only role to access the required incident tables through the Table API.
Configure ServiceNow field-level read ACLs to allow the Nexthink read-only role to access closed notes and resolution notes fields required by the connector.
Do not assign administrative or write-access roles to the Nexthink integration user.
Refer to the Third-party credentials documentation for more information about connector credentials.
Configuring the ServiceNow Incidents connector
From the Nexthink web interface:
Go to Administration > Inbound connectors.
Click the New connector button in the top-right corner of the page.
Select ServiceNow Incidents.
General tab
Name: A meaningful name for the connector. This name appears on the administration page.
NQL ID: A unique identifier for the connector used when referencing the ServiceNow connector in NQL queries. You can initially modify the suggested NQL ID, but once you save the connector, you can no longer change it.
Description: A short description of the purpose and behavior of the connector.
Schedule:
Recurrence: Set the execution time and recurrence. Executions start at the scheduled time and distribute over the hour.
Connection:
Credentials: Select preconfigured credentials from the Connector credentials page. The connector supports OAuth 2.0 and Basic Auth authentication methods. Refer to the Third-party credentials documentation for more information.

Parameters tab
Query (optional): Query to filter ServiceNow incidents.
Start date: Select the date from which data will be synced by the connector.
Custom header: Use a custom header to include additional credential information in OAuth 2.0 authentication methods, such as Client Credentials and Authorization Code. This is useful when additional authorization methods are needed beyond the default OAuth 2.0 authorization mechanism. Select Add custom header to include additional information in either OAuth 2.0 - Client credentials or OAuth 2.0 - Authorization code authorizations.

Test results panel
Use the Test results panel on the right side to run the connector with real data on demand, and inspect responses and errors. The test panel helps with faster debugging and validation during setup, and also with more reliable mappings with less trial and error.
Select the Run test button to call the API, validate the credentials, and check connectivity to the targeted endpoint.

Besides basic information, such as the response status code and time, the panel also shows a sample record of the response at the bottom.

In the event of an error, the system displays the API response to aid in diagnosing the issue.

Last updated
Was this helpful?