LogoClawIndex
CasesSkillsAbout
LogoClawIndex

triaging-security-alerts-in-splunk - Splunk Security Alert Triage

Classify severity, investigate notable events, correlate telemetry in Splunk Enterprise Security

Tags

Updated: 2026-05-09

Capabilities

Typical Inputs

Typical Outputs

What this skill does

  • access incident review dashboard
  • investigate notable events
  • correlate data sources
  • update event status
  • record investigation results
  • track triage metrics

Inputs

  • Splunk Enterprise Security instance
  • notable events queue
  • CIM-normalized data sources
  • threat intelligence feeds

Outputs

  • updated notable event status
  • event classification disposition
  • triage investigation report
  • escalation tickets

Requirements

  • Splunk ES 7.x+
  • CIM-normalized data
  • ess_analyst role
  • SPL knowledge

Source

  • Spec: SKILL.md

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.
soc
splunk
alert-triage
siem
notable-events
correlation-search
incident-review
access incident review dashboard
investigate notable events
correlate data sources
update event status
Splunk Enterprise Security instance
notable events queue
CIM-normalized data sources
updated notable event status
event classification disposition
triage investigation report