triaging-security-alerts-in-splunk - Triaging Security Alerts in Splunk ES
Classifies severity, investigates notable events, correlates telemetry, and makes triage decisions in Splunk Enterprise Security
Tags
Updated: 2026-05-09Capabilities
Typical Inputs
Typical Outputs
What this skill does
- access incident review dashboard
- prioritize notable events
- investigate event context
- correlate data sources
- query threat intelligence
- classify alert disposition
- update event status
- document findings
- track metrics
Inputs
- Splunk Enterprise Security
- CIM-normalized data sources
- Incident Review dashboard
- notable events
- correlation searches
- threat intelligence feeds
Outputs
- triage report
- alert disposition
- notable event status
- incident ticket
- triage metrics
Requirements
- Splunk Enterprise Security 7.x+
- ess_analyst role
- SPL knowledge
- configured Incident Review dashboard
