{"product_id":"splunk-security-alert-webhook-enrichment-with-abuseipdb-email-telegram","title":"Splunk Security Alert Webhook Enrichment with AbuseIPDB + Email \u0026 Telegram","description":"\u003ch3\u003eTurn Splunk security alerts into enriched, deduplicated alerts—instantly\u003c\/h3\u003e\n\u003cp\u003eThis n8n workflow receives \u003cstrong\u003eSplunk security alerts\u003c\/strong\u003e via webhook, detects duplicates within a 15-minute cooldown, enriches public source IPs with \u003cstrong\u003eAbuseIPDB\u003c\/strong\u003e reputation data, calculates a composite risk score, and sends \u003cstrong\u003eseverity-based notifications\u003c\/strong\u003e through \u003cstrong\u003eEmail\u003c\/strong\u003e and \u003cstrong\u003eTelegram\u003c\/strong\u003e—plus a daily digest.\u003c\/p\u003e\n\n\u003ch3\u003eWhat this workflow does\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eIngest \u0026amp; normalize:\u003c\/strong\u003e Accepts Splunk alert payloads using a \u003cstrong\u003ePOST webhook\u003c\/strong\u003e and normalizes key fields including severity, source IP, targeted users\/hosts, event counts, and timestamps.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eDeterministic fingerprinting \u0026amp; deduplication:\u003c\/strong\u003e Creates a fingerprint per alert and checks the \u003cstrong\u003e“Splunk Security Incidents” Data Table\u003c\/strong\u003e for the latest match. If an identical alert is found within a \u003cstrong\u003e15-minute cooldown window\u003c\/strong\u003e, it is suppressed.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eDuplicate handling:\u003c\/strong\u003e Duplicate alerts are stored with a \u003cstrong\u003ezero risk score\u003c\/strong\u003e and \u003cstrong\u003eno notifications\u003c\/strong\u003e are sent.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eAbuseIPDB enrichment:\u003c\/strong\u003e For \u003cstrong\u003epublic IPv4\u003c\/strong\u003e addresses, the workflow enriches with \u003cstrong\u003eAbuseIPDB** reputation data\u003c\/strong\u003e; non-public addresses use default threat-intelligence values.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eComposite risk scoring:\u003c\/strong\u003e Calculates risk using \u003cstrong\u003eSplunk severity\u003c\/strong\u003e, \u003cstrong\u003efailed attempts\u003c\/strong\u003e, \u003cstrong\u003eAbuseIPDB confidence score\u003c\/strong\u003e, and targeted user\/host counts.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eSeverity-based notification routing:\u003c\/strong\u003e Sends \u003cstrong\u003eCritical\/High\u003c\/strong\u003e incidents via \u003cstrong\u003eEmail\u003c\/strong\u003e and \u003cstrong\u003eTelegram\u003c\/strong\u003e, sends \u003cstrong\u003eMedium\u003c\/strong\u003e incidents via \u003cstrong\u003eEmail\u003c\/strong\u003e, and stores \u003cstrong\u003eLow\u003c\/strong\u003e incidents without notification.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eDaily digest:\u003c\/strong\u003e Runs daily at \u003cstrong\u003e18:00\u003c\/strong\u003e to aggregate metrics from the previous 24 hours and email a summary.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eUse cases\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003eReduce alert fatigue by suppressing repeated Splunk detections within 15 minutes.\u003c\/li\u003e\n  \u003cli\u003eSpeed up triage by enriching public source IPs with AbuseIPDB before notifying responders.\u003c\/li\u003e\n  \u003cli\u003eCentralize incident tracking in an n8n Data Table for reporting and daily security metrics.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eTechnical details\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eWebhook\u003c\/strong\u003e (POST) for Splunk ingestion\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eData Table\u003c\/strong\u003e for deduplication and incident storage (“Splunk Security Incidents”)\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eif\u003c\/strong\u003e, \u003cstrong\u003efilter\u003c\/strong\u003e, \u003cstrong\u003ecode\u003c\/strong\u003e, \u003cstrong\u003eno op\u003c\/strong\u003e for workflow logic and routing\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eTelegram\u003c\/strong\u003e for Critical\/High notifications\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eEmail\u003c\/strong\u003e for Medium\/Critical\/High plus the daily digest\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"N8N Commerce","offers":[{"title":"Default Title","offer_id":46086657048755,"sku":"N8N-19906","price":77.99,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0749\/6279\/6723\/files\/gwTO94APaCzcRom63fVn_f2Yzil5j.png?v=1790327385","url":"https:\/\/buyflowscripts.com\/products\/splunk-security-alert-webhook-enrichment-with-abuseipdb-email-telegram","provider":"N8N Commerce","version":"1.0","type":"link"}