# Enrich and route Splunk security alerts via AbuseIPDB, email, and Telegram

> Quick overview This workflow ingests Splunk security alerts via webhook, normalizes and deduplicates them using an n8n Data Table, enriches public source IPs with AbuseIPDB reputation data, calculates a risk score, and sends severity-based notifications via email and Telegram plus a daily email. digest. How it works 1. Receives Splunk alert payloads via a POST webhook and normalizes fields such as severity, source IP, targeted users and hosts, event counts, and timestamps. 2. Generates a deterministic fingerprint for each alert and looks up the latest matching record in the Splunk Security Incidents Data Table to detect duplicates within a 15-minute cooldown window. 3. If the alert is a duplicate, marks it as suppressed with a zero risk score and stores it in the incidents Data Table without sending notifications. 4. If the alert is not a duplicate, checks whether the source IP is a public IPv4 address. Public addresses are enriched with AbuseIPDB reputation data; other addresses conti

- **Domain**: `n8n-workflow-19906.n8n.io`
- **Provider**: n8n.io (https://n8n.io)
- **Kind**: workflow
- **Live-responds (last probe)**: None
- **Signed card**: False
- **Streaming**: False
- **Quality score**: 40%

## URLs
- Agent card: https://n8n.io/workflows/19906
- Page (HTML): https://agenstry.com/agents/n8n-workflow-19906.n8n.io
- Documentation: https://n8n.io/workflows/19906
