{"id":"uD31xU0VYjogxWoY","meta":{"instanceId":"workflow-2d08723c","versionId":"1.0.0","createdAt":"2025-09-29T07:07:55.168604","updatedAt":"2025-09-29T07:07:55.168630","owner":"n8n-user","license":"MIT","category":"automation","status":"active","priority":"high","environment":"production"},"name":"Create_Unique_Jira_tickets_from_Splunk_alerts","nodes":[{"id":"3f9fa220-1966-4478-b7db-c39056564c9d","name":"Webhook","type":"n8n-nodes-base.webhook","position":[-640,320],"webhookId":"f2a52578-2fef-40a6-a7ff-e03f6b751a02","parameters":{"path":"f2a52578-2fef-40a6-a7ff-e03f6b751a02","options":{},"httpMethod":"POST"},"typeVersion":1,"notes":"This webhook node performs automated tasks as part of the workflow."},{"id":"375ac47e-7975-45cb-b7c1-cef1c7fca701","name":"Add Ticket Comment","type":"n8n-nodes-base.jira","position":[240,520],"parameters":{"comment":"=Timestamp: {{ $('Set Host Name').item.json.body.timestamp }}\nDescription: {{ $('Set Host Name').item.json.body.description }}","options":{},"issueKey":"YOUR_CREDENTIAL_HERE","resource":"issueComment"},"credentials":{"jiraSoftwareCloudApi":{"id":"OYvpDV2Q42eY6iyA","name":"Alex Jira Cloud"}},"typeVersion":1,"notes":"This jira node performs automated tasks as part of the workflow."},{"id":"a5dea875-6adf-4d18-aeb9-5fe31a0ebfae","name":"Search Ticket","type":"n8n-nodes-base.jira","position":[-200,320],"parameters":{"options":{"jql":"=splunkhostname ~ \"{{ $json['splunk-host-name'] }}\" "},"operation":"getAll"},"credentials":{"jiraSoftwareCloudApi":{"id":"OYvpDV2Q42eY6iyA","name":"Alex Jira Cloud"}},"typeVersion":1,"alwaysOutputData":true,"notes":"This jira node performs automated tasks as part of the workflow."},{"id":"3dac410e-1e37-463d-9aba-bc6abf3889f7","name":"Set Host Name","type":"n8n-nodes-base.set","position":[-420,320],"parameters":{"values":{"string":[{"name":"splunk-host-name","value":"={{ $json.body.inputs.A.key['host.name'].replace(/[^a-zA-Z0-9 ]/g, '') }}"}]},"options":{}},"typeVersion":2,"notes":"This set node performs automated tasks as part of the workflow."},{"id":"465ec3b0-dd16-482e-b4b6-f8ed91fbb11b","name":"IF Ticket Not Exists","type":"n8n-nodes-base.if","position":[20,320],"parameters":{"conditions":{"string":[{"value1":"={{ $json.key }}","operation":"isEmpty"}]}},"typeVersion":1,"notes":"This if node performs automated tasks as part of the workflow."},{"id":"1315b76b-39fc-4fd3-9a45-a91e5e873874","name":"Sticky Note","type":"n8n-nodes-base.stickyNote","position":[-1120,-26.960531840248223],"parameters":{"width":643.8620281403546,"height":537.944771288002,"content":"![VirusTotal]({{ $env.WEBHOOK_URL }}\n## Webhook Node \nTo setup your webhook integration for Splunk, first ensure that splunk is setup to send alerts to a webhook by visiting the [Setup Guide here]({{ $env.WEBHOOK_URL }} You will copy the n8n webhook url opening the webhook node below. \n- **Form Access URLs**:\n  - **Execute Mode**: `{{ $env.WEBHOOK_URL }}` - Use this to execute the workflow interactively within the n8n canvas. Hit the 'Execute Workflow' button to see real-time execution results. We have pinned data in the webhook node to make testing easier. \n  - **Silent Mode**: `{{ $env.WEBHOOK_URL }}` - Use this for background execution without canvas updates. Results will be logged silently and can be reviewed in the 'Executions' tab."},"typeVersion":1,"notes":"This stickyNote node performs automated tasks as part of the workflow."},{"id":"636425b9-a11f-4891-aa00-2f3c42956c01","name":"Create Ticket","type":"n8n-nodes-base.jira","position":[240,160],"parameters":{"project":{"__rl":true,"mode":"list","value":"10001","cachedResultName":"Service Desk"},"summary":"=Splunk Alert for host {{ $('Set Host Name').item.json.body.inputs.A.key[\"host.name\"] }}:  {{ $('Set Host Name').item.json.body.description }}","issueType":{"__rl":true,"mode":"list","value":"10004","cachedResultName":"[System] Incident"},"additionalFields":{"description":"={{ $('Set Host Name').item.json.body.description }}\n\n{{ $('Set Host Name').item.json.body.messageBody }}","customFieldsUi":{"customFieldsValues":[{"fieldId":{"__rl":true,"mode":"id","value":"customfield_10063"},"fieldValue":"={{ $('Webhook').item.json[\"body\"][\"inputs\"][\"A\"][\"key\"][\"host.name\"].replace(/[^a-zA-Z0-9 ]/g, '') }}"}]}}},"credentials":{"jiraSoftwareCloudApi":{"id":"OYvpDV2Q42eY6iyA","name":"Alex Jira Cloud"}},"typeVersion":1,"notes":"This jira node performs automated tasks as part of the workflow."},{"id":"47af8bdb-e0da-4923-8f0a-05deb86ac1b3","name":"Sticky Note1","type":"n8n-nodes-base.stickyNote","position":[-460,98.72468966845895],"parameters":{"width":401.99970102055784,"height":413.43480804607805,"content":"![VirusTotal]({{ $env.WEBHOOK_URL }}\n## Normalize Hostname \nTo ensure no special characters are passed into jira and create issues, this set node removes special characters from the `splunk-host-name` and uses that to search and create tickets. This host name is saved as a custom field. "},"typeVersion":1,"notes":"This stickyNote node performs automated tasks as part of the workflow."},{"id":"c0bf09e6-ca08-4db6-aff0-a6528a8fb03b","name":"Sticky Note2","type":"n8n-nodes-base.stickyNote","position":[180,-21.934709587377256],"parameters":{"width":401.99970102055784,"height":348.38243930996134,"content":"![VirusTotal]({{ $env.WEBHOOK_URL }}\n## Create a new ticket\nThis creates a new ticket in your Prjoect and issue type. Ensure to update these values to ensure it works correctly. "},"typeVersion":1,"notes":"This stickyNote node performs automated tasks as part of the workflow."},{"id":"a175e343-83ed-4442-94df-7e7027b8c687","name":"Sticky Note3","type":"n8n-nodes-base.stickyNote","position":[180,340],"parameters":{"width":401.99970102055784,"height":341.08777742613927,"content":"![VirusTotal]({{ $env.WEBHOOK_URL }}\n## Add Ticket Comment\nThis adds the alert as a comment in the existing ticket, to ensure the data is not duplicated. "},"typeVersion":1,"notes":"This stickyNote node performs automated tasks as part of the workflow."},{"id":"09143b8c-a4ce-4791-8937-3333d24b6e01","name":"Sticky Note4","type":"n8n-nodes-base.stickyNote","position":[-40,100.50445897107033],"parameters":{"width":193.6032856277124,"height":415.27445353029793,"content":"## Check if ticket found\nThis checks `$json.key` to see if the value was found, and route accordingly."},"typeVersion":1,"notes":"This stickyNote node performs automated tasks as part of the workflow."}],"active":false,"settings":{"executionOrder":"v1","saveManualExecutions":true,"callerPolicy":"workflowsFromSameOwner","errorWorkflow":null,"timezone":"UTC","executionTimeout":3600,"maxExecutions":1000,"retryOnFail":true,"retryCount":3,"retryDelay":1000},"versionId":"3985cac2-7f23-4d27-b826-0edfb0544b58","connections":{"Webhook":{"main":[[],[],[],[],[],[],[],[],[]]}},"description":"Automated workflow: Create_Unique_Jira_tickets_from_Splunk_alerts. This workflow integrates 6 different services: webhook, stickyNote, set, stopAndError, jira. It contains 13 nodes and follows best practices for error handling and security.","notes":"Excellent quality workflow: Create_Unique_Jira_tickets_from_Splunk_alerts. This workflow has been optimized for production use with comprehensive error handling, security, and documentation."}