icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Torq Add-on for Splunk
SHA256 checksum (torq-add-on-for-splunk_100.tgz) 40d1eaef2a7ef410b3197db35d8f7d2d00815a62e3fdac6ee925b04e687bc664
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

splunk

Torq Add-on for Splunk

Splunk Cloud
Overview
Details
The Torq Add-on for Splunk enables security teams to integrate Torq's HyperAutomation platform with Splunk Enterprise and Splunk Enterprise Security. Trigger Torq workflows directly from your Splunk alert actions, or ad-hoc using Adaptive Response actions (when used with Enterprise Security).

Features:
* Alert Action Integration - Trigger Torq workflows from any Splunk alert or saved search
* Enterprise Security Support - Launch workflows as Adaptive Response actions from correlation searches and notable events
* Secure Configuration - Built-in credential management for Torq webhook integrations with authentication header support
* Customizable Payloads - Flexible JSON payload formatting to send relevant Splunk context (search results, metadata, links) to Torq workflows

Configuration

First, create a Splunk integration in Torq as documented here. Make sure to set an authentication header. Note the endpoint URL, header name, and secret.

Next, in Splunk, navigate to the Torq Add-on for Splunk app. Click "Add integration" and enter the
endpoint URL, header name and secret you created in the previous step. Click save.

Now you can trigger your Splunk integration from an alert, correlation search, or ad-hoc as an adaptive response action.

Triggering from a Splunk alert

  1. Find your alert on the "Searches, reports, and alerts" page and click Edit->Edit Alert.
  2. Scroll down to "Trigger Actions", click "Add Actions", and select "Trigger Torq Workflow".
  3. Select the integration you created, and if you wish, customize the payload.
  4. Click save.

Triggering from an Enterprise Security correlation search

  1. Navigate to Configure->Content->Content Management.
  2. Click your correlation search to edit it.
  3. Scroll down to "Adaptive Response Actions" and click "Add New Response Action", then finally "Trigger Torq Workflow".
  4. Select the integration you created, and if you wish, customize the payload.
  5. Click save.

Triggering ad-hoc from Enterprise Security's Incident Review page

  1. Select a notable event and click the arrow in the "Actions" column.
  2. Click "Run adaptive response action", click "Add New Response Action", then finally "Trigger Torq Workflow".
  3. Select the integration you created, and if you wish, customize the payload.
  4. Click run.
  5. With the notable event expanded, click the refresh icon next to "Adaptive Responses".
  6. If the status is "Success", you have successfully triggered your Torq workflow. If not, click "View Adaptive Response Invocations" for information that can help troubleshoot.

Release Notes

Version 1.0.0
Sept. 10, 2025

Initial publication


Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk LLC in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.