There are much simpler and effective ways to do this. Assuming you have ES. Set up your asset configuration for splunk to point to ES . You can send an event through either an automated action inside a saved search, phantom app with a saved search forwarding a specific event to an active playbook or even a adaptive response action. All you need is to pass the ES Notable Event ID, Status and Integer and you should be able to do so. The search provided does the job but here are other options worth considering.
... View more