triaging-security-alerts-in-splunk - Splunk Security Alert Triage
Classify severity, investigate notable events, correlate telemetry in Splunk Enterprise Security
Tags
Updated: 2026-05-09Capabilities
Typical Inputs
Typical Outputs
What this skill does
- access incident review dashboard
- investigate notable events
- correlate data sources
- update event status
- record investigation results
- track triage metrics
Inputs
- Splunk Enterprise Security instance
- notable events queue
- CIM-normalized data sources
- threat intelligence feeds
Outputs
- updated notable event status
- event classification disposition
- triage investigation report
- escalation tickets
Requirements
- Splunk ES 7.x+
- CIM-normalized data
- ess_analyst role
- SPL knowledge
