All templates

Automated Splunk Weekly Alert Reviews

Every Monday, WebRun opens Splunk, reads the alerts that fired over the past seven days, groups them by saved search and host, records the counts and the repeat offenders in an Airtable trend base, and writes a ready-to-read review page in Notion showing what fired most, what is new, and what has gone quiet.

Runs on WebRun · Strict Lockdown policy
Every Monday at 8:00 AM WebRunorchestrates each step
1 Splunk review the week's alerts
2 Airtable record the weekly counts
3 Notion write the review page
In short

How do I run a weekly review of my Splunk alerts?

WebRun reviews a full week of Splunk alerts every Monday, grouping them by saved search and host and counting how often each fired. It records the counts and a four-week trend in Airtable, then writes a Notion review page naming the loudest alerts and the tuning candidates for your ops meeting.

  • The ops review is written before the meeting starts, every week
  • Noisy alerts are named with counts instead of argued about from memory
  • Four-week trends show whether tuning actually worked

Built for site reliability engineers · security operations · IT operations teams · platform engineers

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens splunk.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    Splunk - review the week's alerts
    splunk.com
    WebRun in Splunk: review the week's alerts
    WebRun opens Splunk to review the week's alerts.
    • Open Splunk and list the alerts that fired in the last seven days
    • Group them by saved search, severity, and originating host
    • Count how many times each alert fired and how many distinct hosts it touched
    • Note which alerts are new this week and which fired every single day

    Done when Every alert from the past week is grouped and counted.

  3. 2
    Airtable - record the weekly counts
    airtable.com
    WebRun in Airtable: record the weekly counts
    WebRun opens Airtable to record the weekly counts.
    • Open your alert trend base in Airtable
    • Add a row per alert with this week's fire count, host count, and severity
    • Compare each count against the previous four weeks and mark the direction of travel
    • Tag alerts firing more than your noise threshold as tuning candidates

    Done when This week's counts are recorded with a trend against the last four weeks.

  4. 3
    Notion - write the review page
    notion.so
    WebRun in Notion: write the review page
    WebRun opens Notion to write the review page.
    • Create this week's review page in your ops Notion space
    • Open with the three loudest alerts and the hosts behind them
    • List new alerts, alerts that stopped firing, and the tuning candidates
    • Leave a decisions section empty for the team to fill during the meeting

    Done when The ops team has a written review page in Notion before the meeting.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
splunk.com
ScheduleRuns automatically on this cadence
Every Monday at 8:00 AM
DeliveryHow each run's result reaches you
Weekly alert review · Notion
OutputWhat each run produces - A weekly review of Splunk alerts by saved search and host, with fire counts, four-week trend, new alerts, and tuning candidates.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it disable or edit noisy alerts in Splunk?

No. WebRun only reads alert history. Tuning a saved search, changing a threshold, or disabling an alert is proposed on the Notion page and done by an engineer who decides it is right.

Does it run searches that could load the cluster?

It reads the alert and triggered-alerts views rather than launching heavy ad hoc searches, and it runs once a week at a time you choose, so the load stays predictable.

What if an alert fired thousands of times?

It is grouped into one row with the total count and host spread, and tagged as a tuning candidate, so a single noisy search never buries the rest of the review.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.