Skip to main content

Real-time security threat dashboard with Google Sheets, AI risk analysis & email alerts

Workflow preview

Workflow preview
100%
Real-time security threat dashboard with Google Sheets, AI risk analysis & email alerts preview
Open on n8n.io

Important notice

This workflow is provided as-is. Please review and test before using in production.

1. Workflow Overview

Who it’s for Blue Team leads, CISOs, and SOC managers who want automated visibility into threat metrics, endpoint alerts, and response actions — without needing a full SIEM or BI platform. Great...

Best for

  • SecOps automation workflows
  • advanced n8n builders looking for reusable templates

Tools used

n8n-nodes-base.scheduletrigger, n8n-nodes-base.httprequest, n8n-nodes-base.merge, n8n-nodes-base.code, n8n-nodes-base.if, n8n-nodes-base.emailsend, n8n-nodes-base.googlesheets, n8n-nodes-base.switch

Source and attribution

This workflow is cataloged by N8N Workflows and links back to its original n8n.io source page by Adnan Tariq.

Original n8n.io source

1.1 Workflow description

Title
Real-time security threat dashboard with Google Sheets, AI risk analysis & email alerts
Workflow name
Real-time security threat dashboard with Google Sheets, AI risk analysis & email alerts

👤 Who it’s for Blue Team leads, CISOs, and SOC managers who want automated visibility into threat metrics, endpoint alerts, and response actions — without needing a full SIEM or BI platform.

Great for teams using Modules 1–5 and now ready to report, review, or share BlueOps data across stakeholders.

⚙️ How it works / What it does Fetches threat + response data from up to 5 Google Sheets

Aggregates data into four key slices:

summary_metrics: Total threats, actions, endpoints

daily_trends: Time-based charting

top_assets: High-risk endpoints or systems

actions_taken: Logged IR activity

Generates a clean HTML report and sends via email

Logs report summary to a central reporting tracker sheet

Optionally converts and stores PDF versions or links

🛠️ How to set up Google Sheets: Connect your live sheets from previous BlueOps modules (M1–M5)

Email Setup: Insert sender credentials and recipient(s)

Customize Your Charts: Edit the “📈 Format Charts” and “📋 Structure Report Body” nodes

Trigger Options: Run weekly, monthly, or on-demand via Webhook/Cron

Add PDF Generator (Optional): Use Puppeteer, HTML → PDF services, or internal scripts

📋 Requirements Google account with access to all BlueOps logs

SMTP or Gmail access for report delivery

Optional: PDF storage service or HTML → PDF logic

Previous modules (M1–M5) to populate threat/response data

🧩 How to customize the workflow Swap out Google Sheets for Supabase or Notion

Modify visual output (color, layout, sections) using HTML nodes

Export to Airtable, Slack, or external BI tools

Add chart images using ChartJS, QuickChart API, or CloudConvert

📦 This module is modular, professional, and presentation-ready. All sections are labeled, editable, and safe for team-wide sharing.

📈 This module is the final piece of the CYBERPULSEBlueOps automation suite. Get the full reporting engine and link with live BlueOps modules at 👉 cyberpulsesolutions.com/blueops

1.2 Logical Blocks

This catalog entry is organized from the workflow JSON. The node-level section below shows the executable blocks available for review before importing the template.

2. Block-by-Block Analysis

Block 1 - ⏰ Cron – Daily Trigger

Type / Role
n8n-nodes-base.scheduleTrigger - scheduleTrigger
Config choices
Version 1.2

Block 2 - 🌐 Get CVE Feed

Type / Role
n8n-nodes-base.httpRequest - httpRequest
Config choices
Version 4.2

Block 3 - 🛡️ Get IOC Feed

Type / Role
n8n-nodes-base.httpRequest - httpRequest
Config choices
Version 4.2

Block 4 - 🧠 Merge Threat Data

Type / Role
n8n-nodes-base.merge - merge
Config choices
Version 3.1

Block 5 - 🧠Combine Threat Data

Type / Role
n8n-nodes-base.code - code
Config choices
Version 2

Block 6 - 🧠 AI – Risk Evaluation

Type / Role
n8n-nodes-base.code - code
Config choices
Version 2

Block 7 - 🧠 AI – Triage Vulnerabilities

Type / Role
n8n-nodes-base.code - code
Config choices
Version 2

Block 8 - 🚨 ALERT – LEV Trigger

Type / Role
n8n-nodes-base.if - if
Config choices
Version 2.2

Block 9 - 📧 Send Alert Email

Type / Role
n8n-nodes-base.emailSend - emailSend
Config choices
Version 2.1

Block 10 - Google Sheets

Type / Role
n8n-nodes-base.googleSheets - googleSheets
Config choices
Version 4.5

Block 11 - 🧠 AI – Incident Playbook Selector

Type / Role
n8n-nodes-base.code - code
Config choices
Version 2

Block 12 - Code

Type / Role
n8n-nodes-base.code - code
Config choices
Version 2

Block 13 - 🧭 Response Router

Type / Role
n8n-nodes-base.switch - switch
Config choices
Version 3.2

Block 14 - Send Alert Email

Type / Role
n8n-nodes-base.emailSend - emailSend
Config choices
Version 2.1

Block 15 - Log to Google Sheet

Type / Role
n8n-nodes-base.googleSheets - googleSheets
Config choices
Version 4.5

Block 16 - HTTP Request

Type / Role
n8n-nodes-base.httpRequest - httpRequest
Config choices
Version 4.2

Block 17 - Split Out

Type / Role
n8n-nodes-base.splitOut - splitOut
Config choices
Version 1

Block 18 - Sticky Note

Type / Role
n8n-nodes-base.stickyNote - stickyNote
Config choices
Version 1

Block 19 - Sticky Note1

Type / Role
n8n-nodes-base.stickyNote - stickyNote
Config choices
Version 1

Block 20 - Sticky Note2

Type / Role
n8n-nodes-base.stickyNote - stickyNote
Config choices
Version 1

Block 21 - Sticky Note3

Type / Role
n8n-nodes-base.stickyNote - stickyNote
Config choices
Version 1

3. Summary Table

Workflow Real-time security threat dashboard with Google Sheets, AI risk analysis & email alerts
Complexity advanced
Nodes 21
Categories SecOps
Author Adnan Tariq
Published 25 Jul 2025

4. Reproducing the Workflow from Scratch

  1. 1. Download the workflow JSON

    Use the JSON export at /data/workflows/6415/6415.json as the source template for this automation.

  2. 2. Import the template into n8n

    Open n8n, import the downloaded JSON, and review each node before activating the workflow.

  3. 3. Configure credentials and variables

    Replace placeholder credentials, API keys, webhook URLs, account IDs, and environment-specific values with your own settings.

  4. 4. Test with sample data

    Run the workflow manually or in a staging workspace, inspect node output, and confirm downstream systems receive the expected data.

  5. 5. Activate and monitor

    Enable the workflow only after testing, then monitor executions, errors, and rate limits during the first production runs.

5. General Notes & Resources

Review imported nodes carefully before activation. This catalog entry is intended to help you inspect the workflow structure, understand required services, and find related templates faster.

Node names, credentials, schedules, webhook paths, and external service limits may need adjustment for your workspace.

Frequently asked questions

What does Real-time security threat dashboard with Google Sheets, AI risk analysis & email alerts do?

Who it’s for Blue Team leads, CISOs, and SOC managers who want automated visibility into threat metrics, endpoint alerts, and response actions — without needing a full SIEM or BI platform. Great...

What do I need before importing this workflow?

Review the workflow JSON, configure any required credentials in n8n, and test the automation in a safe workspace before using it in production.

Can I customize this workflow?

Yes. Use the block-by-block analysis and the downloadable JSON to inspect each node, then adjust credentials, prompts, schedules, filters, or destinations for your SecOps use case.