IP reputation check & SOC alerts with Splunk, VirusTotal and AlienVault
IP Reputation Check & Threat Summary using Splunk + VirusTotal + AlienVault + n8n
This workflow automates IP reputation analysis using Splunk alerts, enriches data via VirusTotal and AlienVault OTX, and generates actionable threat summaries for SOC teams — all without any coding.
What It Does
When a Splunk alert contains a suspicious IP:
- Ingests the IP from the Splunk alert via webhook.
- Performs dual threat enrichment using:
- VirusTotal IP reputation & tags.
- AlienVault OTX pulses, reputation & WHOIS.
- Merges & processes threat intel data.
- Generates a rich HTML summary for analyst review.
- Routes action based on severity:
- Sends Slack alert for suspicious IPs.
- Creates an incident in ServiceNow.
- Emails a formatted HTML report to the SOC inbox.
Tech Stack Used
- Splunk – SIEM alert source
- VirusTotal API – Reputation check & analysis stats
- AlienVault OTX API – Community threat intel & pulse info
- n8n – For orchestration, merging, summary generation
- Slack, Gmail, ServiceNow – For SOC notifications and ticketing
Ideal Use Case
Perfect for security teams wanting to:
- Automatically validate IP reputation from SIEM logs
- Get quick context from multiple threat feeds
- Generate email-ready reports and escalate high-risk IPs
Included Nodes
- Webhook (Splunk)
- Function nodes for IOC extraction and intel processing
- HTTP Request (VirusTotal & AlienVault)
- Merge + Switch nodes for conditional logic
- Gmail, Slack, ServiceNow integration
Tips
- Add your VirusTotal and AlienVault credentials in n8n's credential manager.
- Use the Switch node to route based on your internal threat score logic.
- Easily extend this to include AbuseIPDB or GreyNoise for deeper enrichment.
n8n IP Reputation Check and SOC Alert Workflow
This n8n workflow automates the process of checking IP reputation for SOC alerts and notifying relevant teams via Slack, email, or ServiceNow. It's designed to integrate with Splunk, VirusTotal, and AlienVault (though specific API calls for VirusTotal and AlienVault are not explicitly defined in the provided JSON, the structure allows for their integration).
What it does
This workflow streamlines the handling of security alerts by:
- Receiving Alerts: It starts by listening for incoming SOC alerts via a webhook. These alerts are expected to contain IP addresses that need reputation checking.
- IP Reputation Check: It performs an HTTP request, likely to an IP reputation service (e.g., VirusTotal, AlienVault, or a custom threat intelligence feed), to gather information about the provided IP address.
- Conditional Routing: Based on the results of the IP reputation check, it uses a Switch node to route the alert to different notification channels.
- Notification:
- Slack: If certain conditions are met (e.g., high-severity threat), it can post an alert to a designated Slack channel.
- Gmail: It can send an email notification, potentially to a security team or incident responder.
- ServiceNow: It can create or update an incident in ServiceNow for formal incident management.
- Data Transformation (Optional): Includes nodes like
CodeandHTMLwhich can be used for advanced data manipulation, parsing, or formatting of the alert data before sending notifications, though their specific configuration is not detailed in the JSON. - Merging Data: A
Mergenode is present, suggesting that data from different branches or steps might be combined at certain points in the workflow, for example, aggregating reputation results before a final notification.
Prerequisites/Requirements
To use this workflow, you will need:
- n8n Instance: A running n8n instance.
- Webhook Source: A system (e.g., Splunk) configured to send security alerts to the n8n webhook URL.
- API Endpoints: Access to IP reputation APIs (e.g., VirusTotal, AlienVault, or other threat intelligence platforms) and their corresponding API keys/credentials.
- Slack Account: A Slack workspace and a Slack API token/credential configured in n8n for sending messages.
- Gmail Account: A Google account with Gmail access and a Gmail credential configured in n8n for sending emails.
- ServiceNow Account: A ServiceNow instance and credentials configured in n8n for creating/updating incidents.
Setup/Usage
- Import the Workflow: Import the provided JSON into your n8n instance.
- Configure Webhook:
- Activate the
Webhooknode and copy its test or production URL. - Configure your alert source (e.g., Splunk) to send alerts to this URL.
- Activate the
- Configure Credentials:
- Set up credentials for Slack, Gmail, and ServiceNow in your n8n instance.
- Ensure the
HTTP Requestnode is configured with the correct API endpoint and authentication for your chosen IP reputation service.
- Customize Nodes:
- HTTP Request: Adjust the URL, headers, and body to query your specific IP reputation service.
- Switch: Define the conditions for routing alerts based on the reputation check results (e.g.,
if (ip_score > 70)). - Slack: Customize the channel, message content, and formatting for Slack notifications.
- Gmail: Configure the recipient, subject, and body for email alerts.
- ServiceNow: Define the table, fields, and values for creating or updating incidents in ServiceNow.
- Code/HTML: If needed, configure these nodes to transform or parse data according to your requirements.
- Activate the Workflow: Once configured, activate the workflow to start processing alerts.
Related Templates
AI multi-agent executive team for entrepreneurs with Gemini, Perplexity and WhatsApp
This workflow is an AI-powered multi-agent system built for startup founders and small business owners who want to automate decision-making, accountability, research, and communication, all through WhatsApp. The “virtual executive team,” is designed to help small teams to work smarter. This workflow sends you market analysis, market and sales tips, It can also monitor what your competitors are doing using perplexity (Research agent) and help you stay a head, or make better decisions. And when you feeling stuck with your start-up accountability director is creative enough to break the barrier 🎯 Core Features 🧑💼 1. President (Super Agent) Acts as the main controller that coordinates all sub-agents. Routes messages, assigns tasks, and ensures workflow synchronization between the AI Directors. 📊 2. Sales & Marketing Director Uses SerpAPI to search for market opportunities, leads, and trends. Suggests marketing campaigns, keywords, or outreach ideas. Can analyze current engagement metrics to adjust content strategy. 🕵️♀️ 3. Business Research Director Powered by Perplexity AI for competitive and market analysis. Monitors competitor moves, social media engagement, and product changes. Provides concise insights to help the founder adapt and stay ahead. ⏰ 4. Accountability Director Keeps the founder and executive team on track. Sends motivational nudges, task reminders, and progress reports. Promotes consistency and discipline — key traits for early-stage success. 🗓️ 5. Executive Secretary Handles scheduling, email drafting, and reminders. Connects with Google Calendar, Gmail, and Sheets through OAuth. Automates follow-ups, meeting summaries, and notifications directly via WhatsApp. 💬 WhatsApp as the Main Interface Interact naturally with your AI team through WhatsApp Business API. All responses, updates, and summaries are delivered to your chat. Ideal for founders who want to manage operations on the go. ⚙️ How It Works Trigger: The workflow starts from a WhatsApp Trigger node (via Meta Developer Account). Routing: The President agent analyzes the incoming message and determines which Director should handle it. Processing: Marketing or sales queries go to the Sales & Marketing Director. Research questions are handled by the Business Research Director. Accountability tasks are assigned to the Accountability Director. Scheduling or communication requests are managed by the Secretary. Collaboration: Each sub-agent returns results to the President, who summarizes and sends the reply back via WhatsApp. Memory: Context is maintained between sessions, ensuring personalized and coherent communication. 🧩 Integrations Required Gemini API – for general intelligence and task reasoning Supabase- for RAG and postgres persistent memory Perplexity API – for business and competitor analysis SerpAPI – for market research and opportunity scouting Google OAuth – to connect Sheets, Calendar, and Gmail WhatsApp Business API – for message triggers and responses 🚀 Benefits Acts like a team of tireless employees available 24/7. Saves time by automating research, reminders, and communication. Enhances accountability and strategy consistency for founders. Keeps operations centralized in a simple WhatsApp interface. 🧰 Setup Steps Create API credentials for: WhatsApp (via Meta Developer Account) Gemini, Perplexity, and SerpAPI Google OAuth (Sheets, Calendar, Gmail) Create a supabase account at supabase Add the credentials in the corresponding n8n nodes. Customize the system prompts for each Director based on your startup’s needs. Activate and start interacting with your virtual executive team on WhatsApp. Use Case You are a small organisation or start-up that can not afford hiring; marketing department, research department and secretar office, then this workflow is for you 💡 Need Customization? Want to tailor it for your startup or integrate with CRM tools like Notion or HubSpot? You can easily extend the workflow or contact the creator for personalized support. Consider adjusting the system prompt to suite your business
Automated YouTube video uploads with 12h interval scheduling in JST
This workflow automates a batch upload of multiple videos to YouTube, spacing each upload 12 hours apart in Japan Standard Time (UTC+9) and automatically adding them to a playlist. ⚙️ Workflow Logic Manual Trigger — Starts the workflow manually. List Video Files — Uses a shell command to find all .mp4 files under the specified directory (/opt/downloads/单词卡/A1-A2). Sort and Generate Items — Sorts videos by day number (dayXX) extracted from filenames and assigns a sequential order value. Calculate Publish Schedule (+12h Interval) — Computes the next rounded JST hour plus a configurable buffer (default 30 min). Staggers each video’s scheduled time by order × 12 hours. Converts JST back to UTC for YouTube’s publishAt field. Split in Batches (1 per video) — Iterates over each video item. Read Video File — Loads the corresponding video from disk. Upload to YouTube (Scheduled) — Uploads the video privately with the computed publishAtUtc. Add to Playlist — Adds the newly uploaded video to the target playlist. 🕒 Highlights Timezone-safe: Pure UTC ↔ JST conversion avoids double-offset errors. Sequential scheduling: Ensures each upload is 12 hours apart to prevent clustering. Customizable: Change SPANHOURS, BUFFERMIN, or directory paths easily. Retry-ready: Each upload and playlist step has retry logic to handle transient errors. 💡 Typical Use Cases Multi-part educational video series (e.g., A1–A2 English learning). Regular content release cadence without manual scheduling. Automated YouTube publishing pipelines for pre-produced content. --- Author: Zane Category: Automation / YouTube / Scheduler Timezone: JST (UTC+09:00)
Dynamic Hubspot lead routing with GPT-4 and Airtable sales team distribution
AI Agent for Dynamic Lead Distribution (HubSpot + Airtable) 🧠 AI-Powered Lead Routing and Sales Team Distribution This intelligent n8n workflow automates end-to-end lead qualification and allocation by integrating HubSpot, Airtable, OpenAI, Gmail, and Slack. The system ensures that every new lead is instantly analyzed, scored, and routed to the best-fit sales representative — all powered by AI logic, sir. --- 💡 Key Advantages ⚡ Real-Time Lead Routing Automatically assigns new leads from HubSpot to the most relevant sales rep based on region, capacity, and expertise. 🧠 AI Qualification Engine An OpenAI-powered Agent evaluates the lead’s industry, region, and needs to generate a persona summary and routing rationale. 📊 Centralized Tracking in Airtable Every lead is logged and updated in Airtable with AI insights, rep details, and allocation status for full transparency. 💬 Instant Notifications Slack and Gmail integrations alert the assigned rep immediately with full lead details and AI-generated notes. 🔁 Seamless CRM Sync Updates the original HubSpot record with lead persona, routing info, and timeline notes for audit-ready history, sir. --- ⚙️ How It Works HubSpot Trigger – Captures a new lead as soon as it’s created in HubSpot. Fetch Contact Data – Retrieves all relevant fields like name, company, and industry. Clean & Format Data – A Code node standardizes and structures the data for consistency. Airtable Record Creation – Logs the lead data into the “Leads” table for centralized tracking. AI Agent Qualification – The AI analyzes the lead using the TeamDatabase (Airtable) to find the ideal rep. Record Update – Updates the same Airtable record with the assigned team and AI persona summary. Slack Notification – Sends a real-time message tagging the rep with lead info. Gmail Notification – Sends a personalized handoff email with context and follow-up actions. HubSpot Sync – Updates the original contact in HubSpot with the assignment details and AI rationale, sir. --- 🛠️ Setup Steps Trigger Node: HubSpot → Detect new leads. HubSpot Node: Retrieve complete lead details. Code Node: Clean and normalize data. Airtable Node: Log lead info in the “Leads” table. AI Agent Node: Process lead and match with sales team. Slack Node: Notify the designated representative. Gmail Node: Email the rep with details. HubSpot Node: Update CRM with AI summary and allocation status, sir. --- 🔐 Credentials Required HubSpot OAuth2 API – To fetch and update leads. Airtable Personal Access Token – To store and update lead data. OpenAI API – To power the AI qualification and matching logic. Slack OAuth2 – For sending team notifications. Gmail OAuth2 – For automatic email alerts to assigned reps, sir. --- 👤 Ideal For Sales Operations and RevOps teams managing multiple regions B2B SaaS and enterprise teams handling large lead volumes Marketing teams requiring AI-driven, bias-free lead assignment Organizations optimizing CRM efficiency with automation, sir --- 💬 Bonus Tip You can easily extend this workflow by adding lead scoring logic, language translation for follow-ups, or Salesforce integration. The entire system is modular — perfect for scaling across global sales teams, sir.