LogoClawIndex
CasesSkillsAbout
LogoClawIndex

triaging-security-alerts-in-splunk - Splunk Security Alert Triage Skill

Classifies security alerts in Splunk Enterprise Security by investigating notable events and making disposition decisions

Tags

Updated: 2026-05-09

Capabilities

Typical Inputs

Typical Outputs

What this skill does

  • access Incident Review dashboard
  • prioritize alert queue
  • investigate notable events
  • correlate telemetry data
  • query threat intelligence
  • classify alert severity
  • update event status
  • document findings

Inputs

  • Splunk Enterprise Security instance
  • CIM-normalized data sources
  • Incident Review dashboard
  • asset lookup tables
  • identity lookup tables
  • threat intelligence feeds

Outputs

  • triage report
  • alert disposition status
  • updated notable events
  • triage metrics

Requirements

  • Splunk Enterprise Security 7.x+
  • Incident Review dashboard
  • CIM-normalized data sources
  • ess_analyst capability
  • SPL knowledge

Source

  • Spec: SKILL.md

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.
SOC
Splunk
alert triage
SIEM
notable events
correlation search
incident review
cybersecurity
access Incident Review dashboard
prioritize alert queue
investigate notable events
correlate telemetry data
Splunk Enterprise Security instance
CIM-normalized data sources
Incident Review dashboard
triage report
alert disposition status
updated notable events