Security Operations Integration - Splunk Sightings Search workflow Security Operations - Splunk Sightings Search workflow is the implementation for the Splunk integration launched by the Security Operations Integration - Sightings Search workflow. Before you beginRole required: sn_si_analyst About this task Workflow process activities include: Execution Tracking - Begin (Observables) activity Collect Splunk Configurations activity Capability Execution Tracking - Failure activity Checks to see if the MID Server is running or not. Splunk Event Query activity Persist Observable Sightings activity - returns search results in an array. Capability Execution Tracking - Complete activity Execution Tracking - Begin (Observables) activityThe Execution Tracking - Begin (Observables) workflow activity starts the auditing process for a Security Operations Integration workflow that operates on observables. Collect Splunk Configurations activityThe Collect Splunk Configurations workflow activity gathers configuration information to use in the workflow.Splunk Event Query activityThe Splunk Event Query workflow activity searches the Splunk event logs for malicious indicators.Persist Observable Sightings activityThe Persistent Observable Sightings workflow activity retrieves observables from the third-party integration.