triaging-security-alerts-in-splunk - Triage security alerts in Splunk Enterprise Security
Triages security alerts in Splunk Enterprise Security by classifying severity, investigating events, correlating telemetry, and making escalation decisions.
Tags
Updated: 2026-09-20Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Classify alert severity
- Investigate notable event context
- Correlate telemetry across sources
- Query threat intelligence framework
- Update notable event status
- Document triage findings
- Track triage metrics
Inputs
- Queued notable events
- CIM-normalized telemetry data
- Asset and identity lookups
- Threat intelligence feeds
Outputs
- Updated notable event status
- Documented triage report
- Escalated incident tickets
Requirements
- Splunk Enterprise Security 7.x+
- Incident Review dashboard configured
- Role with ess_analyst capability
- CIM-normalized data sources
