# New Alert Fired (Instant) — Splunk

> Emit new event when a new alert is triggered in Splunk. See the documentation

- Key: `splunk-new-alert-fired`
- Type: Trigger (Instant)
- Version: 0.0.2
- App: Splunk (`splunk`) — https://pipedream.com/apps/splunk.md
- This page (HTML): https://pipedream.com/apps/splunk/triggers/new-alert-fired
- Source: https://github.com/PipedreamHQ/pipedream/blob/master/components/splunk/sources/new-alert-fired/new-alert-fired.mjs

## Description

Emit new event when a new alert is triggered in Splunk. [See the documentation](https://docs.splunk.com/Documentation/Splunk/9.4.1/RESTREF/RESTsearch#alerts.2Ffired_alerts)

## Props

| Prop | Type | Required | Description |
|---|---|---|---|
| `savedSearchName` | `string` | Yes | The name of a saved search Options are loaded from the connected account. |

## Returns

Events emitted by Splunk.

## Run it

**TypeScript**

```ts
import { PipedreamClient } from "@pipedream/sdk"

const pd = new PipedreamClient({
  projectId: process.env.PIPEDREAM_PROJECT_ID!,
  clientId: process.env.PIPEDREAM_CLIENT_ID!,
  clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
  projectEnvironment: "production",
})

const deployed = await pd.triggers.deploy({
  id: "splunk-new-alert-fired",
  externalUserId: "{external_user_id}", // any stable ID for this user in your system
  configuredProps: {
    splunk: { authProvisionId: "apn_xxxxxxx" },
    savedSearchName: "Saved Search Name",
  },
  webhookUrl: "https://example.com/webhooks/splunk",
})

console.log(deployed.id)
```

**cURL**

```bash
curl -X POST https://api.pipedream.com/v1/connect/{project_id}/triggers/deploy \
  -H "Content-Type: application/json" \
  -H "X-PD-Environment: production" \
  -H "Authorization: Bearer {access_token}" \
  -d '{
    "external_user_id": "{external_user_id}",
    "id": "splunk-new-alert-fired",
    "webhook_url": "https://example.com/webhooks/splunk",
    "configured_props": {
      "splunk": { "authProvisionId": "apn_xxxxxxx" },
      "savedSearchName": "Saved Search Name"
    }
  }'
```

**MCP**

MCP servers expose Splunk actions as on-demand tools.

New Alert Fired (Instant) is an event source, so your application deploys it with the Connect SDK or API and then either receives each event at a webhook URL or retrieves events on demand with the trigger events API.

## Event delivery

Every event is sent to the HTTP endpoint you choose when you deploy the source. Or: no webhook required — your app or agent can fetch recent events from the [trigger events API](https://pipedream.com/docs/connect/api-reference/list-trigger-events.md) instead.

---

- App: https://pipedream.com/apps/splunk.md · All apps: https://pipedream.com/apps
