How it works...

When your search results are rendered in the event listing, Splunk will match the returned fields and event types with the workflow actions you have configured, and present the dropdown workflow actions as required. In this case, the clientip field was matched with the ARIN workflow action you created.

The basic GET link method used in this recipe will insert the variable value into the URI for the user to click on. In this case, the $clientip$ field variable inserts the IP address into the ARIN query URI, so that the IP is passed within the URI when it is clicked on. Other link methods are available and covered in other recipes in this chapter.

Workflow actions can be made to appear in both the Event Actions drop-down menu ...

Get Splunk Operational Intelligence Cookbook - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.