This Story runs when Splunk Correlated Alert fires off in Splunk ES. It will auto-assign a notable event to the progress status, owner, and comment of your choosing. The story demonstrates how to enrich an IP from the Notable in VirusTotal, open a Tines case, and write VirusTotal votes back into the Splunk notable. The analyst will have the option to push the Tines case to ServiceNow through a Tines page upon request.
How it works
Import this story to your tenant, from where you can adapt it to meet your unique needs.
Import