Splunk Incident Management (`splunkIM`) provides a lightweight, enterprise-grade incident response framework built natively for Splunk Core. Designed as an efficient alternative to heavy enterprise suites, `splunkIM` solves the critical challenge of alert fatigue by grouping disparate search alerts into actionable incident episodes.
Key Features & Capabilities:
• Smart Incident Aggregation: Consolidates raw summary alerts by entity host and category using a rolling 24-hour aggregation window.
• KV Store State Persistence: Stores and tracks incident states (New, Active, In Progress, Pending, Resolved) with full user attribution and edit history.
• Dynamic Incident Review Console: Feature-rich triage drawer allows SOC analysts to update severity, assign owners, add notes, and drill down into underlying summary events without leaving the console.
• SLA & Operational Analytics: Out-of-the-box dashboards tracking Mean Time to Acknowledge (MTTA), Mean Time to Resolve (MTTR), severity distribution, and workload per analyst.
• Automatic Episode Re-opening: Re-triggers existing resolved incidents if a matching alert fires within 24 hours of resolution.
• Turnkey Alert Integration: Easily route custom saved searches into `splunkIM` using standard summary indexing.