August 12, 2026
Security Alerts
Security Alerts App allows you to manage your alerts from any index using SPL query (or from multiple indexes)Built by adnan alshammarySplunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4
Log in to rate this app
Security Alerts App allows you to manage your alerts from any index ( or multiple indexes) based on SPL query. It can be used to manage alerts for different team within SOC (threat hunting , compromised assessments, or threat intelligence team, …). the App define two custom roles: - secalerts_analyst - secalerts_admin "secalerts_analyst" role is the minimum role needed to manage the alerts (by selecting alerts and click "Edit" button): - add comment - update alert status or disposition - assign alert(s) to specific user Two Splunk SOAR playbooks were developed to interact with the App ( retrieving alerts , add comment , update alert status , …etc). for more information about the playbooks and more details about the App find below github link: https://github.com/Adnan-Alshammary/SecurityAlerts/ installation: - the App requires new version of Splunk enterprise (10.4 or later) - restart the Search Head is required after installing the App - the App support search head cluster since its maintain kvstore and lookup files to manage the alerts.
Log in to report this app listing.