Knowledge Management

How do you set up a GET Workflow Action that links a field directly to an event on an AV web interface?

psmaan
New Member

I have an event coming from an antivirus. Antivirus logs contain a field (lets say "URL") which contain direct links to the event on an AV web interface. If I copy that link and paste it in the browser, it will work fine.

I am trying to create a workflow action where a security analyst can click on this link directly from the event field and can open it in a new window. I created a workflow action configuration as described in here:-
https://docs.splunk.com/Documentation/Splunk/7.1.2/Knowledge/SetupaGETworkflowaction

However instead, Splunk is giving me an option to search the AV url link in Google. How do I fix this?

0 Karma

psmaan
New Member

I managed to get this done by breaking up the URL provided in the events as per format required in the URI field of the workflow configuration. However, I would still be interested in a solution where you can use such event fields directly.

0 Karma

mdicenzo
Explorer

I am trying to do this same thing. Can you clarify what you did to get this to work?

The field name is URL and the string already has https so I was trying to just put $!URL$ in the url link configuration.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...