Execute your Twilio Studio Flow from Splunk alert actions.
The search must return @To and @From fields (mandatory for Twilio's API). Other search result fields can be sent to the Flow's Parameters.
The following "metadata" about the search is always sent to Twilio:
- search_name
- sid
- rid
The sid and rid can be used to call back to Splunk Enterprise Security and update a notable (for example, add a user's SMS reply to a notable)