Run Splunk searches, manage saved searches and users, and send events via HEC. Automate Splunk deploys, issues, and webhooks into chat, tickets, or status pages.
Get Export Search ResultsReturns the export Search Results.
Get Field AliasReturns the field Alias.
Get Field ExtractionReturns the field Extraction.
Get Fired AlertReturns the fired Alert.
Get HEC HealthReturns the hEC Health.
Get HTTP InputReturns the hTTP Input.
Get IndexReturns the index.
Get KV Store CollectionReturns the kV Store Collection.
Get KV Store RecordReturns the kV Store Record.
Get Local AppReturns the local App.
Get LookupReturns the lookup.
Get MacroReturns the macro.
Get MessageReturns the message.
Get PanelReturns the panel.
Get Parsed SearchReturns the parsed Search.
Get RoleReturns the role.
Get Saved SearchReturns the saved Search.
Get Saved Search HistoryReturns the saved Search History.
Get Saved Search Scheduled TimesReturns the saved Search Scheduled Times.
Get Search JobReturns the search Job.
Get Search Job EventsReturns the search Job Events.
Get Search Job LogReturns the search Job Log.
Get Search Job ResultsReturns the search Job Results.
Get Search Job Results PreviewReturns the search Job Results Preview.
Get Search Job SummaryReturns the search Job Summary.
Get Search Job TimelineReturns the search Job Timeline.
Get Server InfoReturns the server Info.
Get TagReturns the tag.
Get TCP InputReturns the tCP Input.
Get TimeparserReturns the timeparser.
Get TokenReturns the token.
Get TransformReturns the transform.
Get UDP InputReturns the uDP Input.
Get UserReturns the user.
Get ViewReturns the view.
List Alert ActionsRetrieves a list of the alert Actions.
List CapabilitiesRetrieves a list of the capabilities.
List ConfigsRetrieves a list of the configs.
List Data ModelsRetrieves a list of the data Models.
List Event TypesRetrieves a list of the event Types.
List Field AliasesRetrieves a list of the field Aliases.
List Field ExtractionsRetrieves a list of the field Extractions.
List Fired AlertsRetrieves a list of the fired Alerts.
List HTTP InputsRetrieves a list of the hTTP Inputs.
List IndexesRetrieves a list of the indexes.
List InputsRetrieves a list of the inputs.
List KV Store CollectionsRetrieves a list of the kV Store Collections.
List KV Store RecordsRetrieves a list of the kV Store Records.
List Local AppsRetrieves a list of the local Apps.
List LookupsRetrieves a list of the lookups.
List MacrosRetrieves a list of the macros.
List MessagesRetrieves a list of the messages.
List Modular InputsRetrieves a list of the modular Inputs.
List PanelsRetrieves a list of the panels.
List RolesRetrieves a list of the roles.
List Saved SearchesRetrieves a list of the saved Searches.
List Saved Searches By NamespaceRetrieves a list of the saved Searches By Namespace.
List Search JobsRetrieves a list of the search Jobs.
List Search Jobs By NamespaceRetrieves a list of the search Jobs By Namespace.
List TagsRetrieves a list of the tags.
List TCP InputsRetrieves a list of the tCP Inputs.
List TokensRetrieves a list of the tokens.
List TransformsRetrieves a list of the transforms.
List UDP InputsRetrieves a list of the uDP Inputs.
List UsersRetrieves a list of the users.
List ViewsRetrieves a list of the views.
Search TypeaheadSearches the typeahead.
Acknowledge Saved SearchAcknowledges the saved Search.
Control Search JobControls the search Job.
Create Automatic LookupCreates the automatic Lookup.
Create Calculated FieldCreates the calculated Field.
Create Data ModelCreates the data Model.
Create Event TypeCreates the event Type.
Create Field AliasCreates the field Alias.
Create Field ExtractionCreates the field Extraction.
Create HTTP InputCreates the hTTP Input.
Create IndexCreates the index.
Create KV Store CollectionCreates the kV Store Collection.
Create KV Store RecordCreates the kV Store Record.
Create Local AppCreates the local App.
Create LookupCreates the lookup.
Create MacroCreates the macro.
Create MessageCreates the message.
Create PanelCreates the panel.
Create RoleCreates the role.
Create Saved SearchCreates the saved Search.
Create Search JobCreates the search Job.
Create TagCreates the tag.
Create TCP InputCreates the tCP Input.
Create TokenCreates the token.
Create TransformCreates the transform.
Create UDP InputCreates the uDP Input.
Create UserCreates the user.
Create ViewCreates the view.
Create Workflow ActionCreates the workflow Action.
Delete Event TypeDeletes the event Type.
Delete Fired AlertDeletes the fired Alert.
Delete HTTP InputDeletes the hTTP Input.
Delete IndexDeletes the index.
Delete KV Store CollectionDeletes the kV Store Collection.
Delete KV Store RecordDeletes the kV Store Record.
Delete Local AppDeletes the local App.
Delete LookupDeletes the lookup.
Delete MacroDeletes the macro.
Delete MessageDeletes the message.
Delete RoleDeletes the role.
Delete Saved SearchDeletes the saved Search.
Delete Search JobDeletes the search Job.
Delete TagDeletes the tag.
Delete UserDeletes the user.
Disable Saved SearchPerforms the disable Saved Search operation.
Dispatch Saved SearchPerforms the dispatch Saved Search operation.
Enable Local AppPerforms the enable Local App operation.
Enable Saved SearchPerforms the enable Saved Search operation.
Make an API CallPerforms an arbitrary authorized API call.
Reload IndexPerforms the reload Index operation.
Restart Local AppPerforms the restart Local App operation.
Send HEC EventSends the hEC Event.
Send HEC RawSends the hEC Raw.
Suppress Saved SearchPerforms the suppress Saved Search operation.
Update Data ModelUpdates the data Model.
Update Event TypeUpdates the event Type.
Update Field AliasUpdates the field Alias.
Update Field ExtractionUpdates the field Extraction.
Update HTTP InputUpdates the hTTP Input.
Update IndexUpdates the index.
Update KV Store RecordUpdates the kV Store Record.
Update Local AppUpdates the local App.
Update LookupUpdates the lookup.
Update MacroUpdates the macro.
Update MessageUpdates the message.
Update PanelUpdates the panel.
Update RoleUpdates the role.
Update Saved SearchUpdates the saved Search.
Update Saved Search ScheduleUpdates the saved Search Schedule.
Update Search JobUpdates the search Job.
Update TagUpdates the tag.
Update TCP InputUpdates the tCP Input.
Update TransformUpdates the transform.
Update UDP InputUpdates the uDP Input.
Update UserUpdates the user.
Update ViewUpdates the view.
Upload Lookup FileUploads the lookup File.
When to use Splunk
Common scenarios where Splunk automation saves time and reduces manual work.
Use Splunk's "Watch Fired Alerts" trigger to react the instant an event occurs and push data into connected tools.
Automate "Get Config" in Splunk as a workflow step — combine it with triggers, filters, and AI steps for full-pipeline coverage.
Combine "Get Alert Action" from Splunk with triggers or actions in other apps to close the loop — one event, many downstream outcomes.
Frequently asked questions
Common questions about automating Splunk in your workflows.
Splunk has 2 triggers, including "Watch Fired Alerts" and "Watch Search Job Done". Use them to start workflows the moment Splunk events fire — no polling required.
Connect Splunk to any app in workflows
Search apps and open an app-to-app integration page in one click.