August 27, 2026
Nuclea Alert Enhancer
Enriches Splunk Enterprise Security alerts with AI-generated SOC playbooks and mitigation steps using Google Gemini, posting analysis as notes to ES findings.Built by DataRunk, an official Splunk PartnerSplunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4
Log in to rate this app
The Nuclea Alert Enhancer integrates Google Gemini AI with Splunk Enterprise Security to enrich security alerts and findings with AI-generated analysis. When an ES alert fires, the app generates contextual SOC playbooks, mitigation steps, and threat analysis using Google Gemini's large language model. The generated insights are automatically posted as notes to ES investigations, enabling security analysts to access AI-assisted triage and response guidance directly within their existing workflows. The app provides a custom alert action for enrichment and a streaming command for posting LLM responses to the ES investigations API. Configuration and ROI tracking dashboards allow administrators to manage API credentials, monitor enrichment activity, and measure the impact of AI-assisted analysis on security operations. The app requires a valid Google Gemini API key and an operational Splunk Enterprise Security deployment.
Log in to report this app listing.