๐Ÿ”’ IP reputation check & SOC alerts with Splunk, VirusTotal and AlienVault

โšก 1,877 views ยท ๐Ÿ”’ SecOps & Security Automation

Description

IP Reputation Check & Threat Summary using Splunk + VirusTotal + AlienVault + n8n

This workflow automates IP reputation analysis using Splunk alerts, enriches data via VirusTotal and AlienVault OTX, and generates actionable threat summaries for SOC teams โ€” all without any coding.


What It Does

When a Splunk alert contains a suspicious IP:


Tech Stack Used


Ideal Use Case

Perfect for security teams wanting to:


Included Nodes


Tips

๐Ÿ”— Nodes Used

HTTP Request, Slack, Webhook, Gmail, ServiceNow

๐Ÿ“ฅ Import

Download workflow.json and import into n8n: Workflow menu โ†’ Import from File

๐Ÿ“– Importing guide ยท ๐Ÿ”‘ Credential setup