Skip to main content
Security Alerts app icon

Security Alerts

Security Alerts App allows you to manage your alerts from any index using SPL query (or from multiple indexes)Built by adnan alshammary
splunk product badge

Default Version 0.1.0

August 12, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4

Rating
0
(0)

Log in to rate this app

Support
Not Supported

Security Alerts App allows you to manage your alerts from any index ( or multiple indexes) based on SPL query. It can be used to manage alerts for different team within SOC (threat hunting , compromised assessments, or threat intelligence team, …). the App define two custom roles: - secalerts_analyst - secalerts_admin "secalerts_analyst" role is the minimum role needed to manage the alerts (by selecting alerts and click "Edit" button): - add comment - update alert status or disposition - assign alert(s) to specific user Two Splunk SOAR playbooks were developed to interact with the App ( retrieving alerts , add comment , update alert status , …etc). for more information about the playbooks and more details about the App find below github link: https://github.com/Adnan-Alshammary/SecurityAlerts/ installation: - the App requires new version of Splunk enterprise (10.4 or later) - restart the Search Head is required after installing the App - the App support search head cluster since its maintain kvstore and lookup files to manage the alerts.