Splunk® Intelligence Management (Legacy)

Workflow Apps

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

Overview of workflow applications in Splunk Intelligence Management

Use the workflow applications in Splunk Intelligence Management for Splunk Enterprise and Splunk Enterprise Security for the following detection use cases:

  • Detect: Automate the matching of highly-scored indicators into your detection tool to optimize detection workflows for better accuracy. You can also customize data ingest preferences to reduce false positive rate.
  • Investigate: Display Splunk Intelligence Management's enrichment data in your existing workflows and applications for more context into indicators and events.
  • Triage: Automatically prioritize events based on normalized scores from your internal and external data sources. Connect those indicators and events with detection, incident response, and orchestration tools to trigger further actions.
Last modified on 11 July, 2022
 

This documentation applies to the following versions of Splunk® Intelligence Management (Legacy): current


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters