Splunk ES Integration for Security Operations
Create security response incidents automatically from Splunk Enterprise Security Notable Events.
Install Trend
View Install Data
| Date | Install Count | Change |
|---|---|---|
| 2026-09-09 | 0 | - |
| 134 days of no change | ||
| 2026-04-27 | 150 | -150 |
| 165 days of no change | ||
| 2025-11-12 | 149 | +1 |
| 12 days of no change | ||
| 2025-10-30 | 148 | +1 |
| 7 days of no change | ||
| 2025-10-22 | 147 | +1 |
| 32 days of no change | ||
| 2025-09-19 | 146 | +1 |
| 18 days of no change | ||
| 2025-08-31 | 145 | +1 |
| 47 days of no change | ||
| 2025-07-14 | 144 | +1 |
| 20 days of no change | ||
| 2025-06-23 | 143 | +1 |
| 55 days of no change | ||
| 2025-04-28 | 142 | +1 |
| 3 days of no change | ||
| 2025-04-24 | 141 | +1 |
| 15 days of no change | ||
| 2025-04-08 | 140 | +1 |
| 6 days of no change | ||
| 2025-04-01 | 139 | +1 |
| 17 days of no change | ||
| 2025-03-14 | 138 | +1 |
| 8 days of no change | ||
| 2025-03-05 | 137 | +1 |
| 2025-03-04 | 136 | +1 |
| 13 days of no change | ||
| 2025-02-18 | 135 | +1 |
| 22 days of no change | ||
| 2025-01-26 | 134 | +1 |
| 8 days of no change | ||
| 2025-01-17 | 133 | +1 |
| 78 days of no change | ||
| 2024-10-30 | 130 | +3 |
About
The Splunk ES Event Ingestion integration for Security Operations allows security operations center (SOC) analysts to generate Now Platform® Security Incident Response (SIR) incidents automatically when certain configured Splunk ES Notable Events are triggered. Analysts can also manually forward selected events on-demand from the Splunk ES console. Analysts respond to the security incidents that are created with workflows in the Now Platform that automate incident response activities and remediation.
Key Features
This integration includes the following key features:
- Create multiple alert ingestion profiles to create SIR security incidents for specific types of threats, such as phishing and malware.
- Create multiple event profiles for on-demand event forwarding from your Splunk ES console to create SIR security incidents
- Drag-and-drop mapping of Splunk ES notable events and event field values to associated SIR security incident fields.
- A SIR security incident layout preview based on sample alerts or events to validate profile configuration.
- Ingest historical alerts and ongoing or future alerts at configurable intervals.
- Aggregate events or alerts to existing SIR security incidents based on matching field values to avoid duplicate security incidents.
Version History (12)
+ 2 more versions