---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Splunk event actions

# Splunk event actions {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

When reviewing Splunk logs, you can rapidly create security events and security
incidents from any item in the log using the Event Actions.

Clicking either of these actions creates a manual search command populated with the data in the
log entry, and run it to generate the new record.

These actions are easily configured to add fields in your normalized data. Within Splunk, using SettingsFieldsWorkflow Actions, you can select and edit either of these actions using the manual search
fields.

You can choose where the action is shown, for what fields, and modify the search string that
contains a search command to create your record.

*[\>]: and then


