<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk ES Adaptive Response | Custom Local Scripts using Dynamic Variables to query external APIs in Other Usage</title>
    <link>https://community.splunk.com/t5/Other-Usage/Splunk-ES-Adaptive-Response-Custom-Local-Scripts-using-Dynamic/m-p/676640#M1682</link>
    <description>&lt;P&gt;Hey Everyone!&lt;/P&gt;&lt;P&gt;We just started using Splunk ES, we just got it up and running fairly well and I have a couple questions hopefully I could get some guidance on or maybe a point in the right direction. I would like to somehow setup the ability for analyst to be able to run local scripts in the adaptive response that use dynamic user input as variables to query external APIs. Another scenario, I was hoping we could use, would be using specific tokens/fields as the dynamic variable for these scripts and just give the analyst the output in the adaptive response when they are ran. Are any of these scenarios possible with ES we have tried to find a way to do this but so far have not come up with any successful implementation. Is there any documentation on implementing something like this? Any help would be very much appreciated!&lt;/P&gt;</description>
    <pubDate>Mon, 05 Feb 2024 20:15:07 GMT</pubDate>
    <dc:creator>treven</dc:creator>
    <dc:date>2024-02-05T20:15:07Z</dc:date>
    <item>
      <title>Splunk ES Adaptive Response | Custom Local Scripts using Dynamic Variables to query external APIs</title>
      <link>https://community.splunk.com/t5/Other-Usage/Splunk-ES-Adaptive-Response-Custom-Local-Scripts-using-Dynamic/m-p/676640#M1682</link>
      <description>&lt;P&gt;Hey Everyone!&lt;/P&gt;&lt;P&gt;We just started using Splunk ES, we just got it up and running fairly well and I have a couple questions hopefully I could get some guidance on or maybe a point in the right direction. I would like to somehow setup the ability for analyst to be able to run local scripts in the adaptive response that use dynamic user input as variables to query external APIs. Another scenario, I was hoping we could use, would be using specific tokens/fields as the dynamic variable for these scripts and just give the analyst the output in the adaptive response when they are ran. Are any of these scenarios possible with ES we have tried to find a way to do this but so far have not come up with any successful implementation. Is there any documentation on implementing something like this? Any help would be very much appreciated!&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2024 20:15:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/Splunk-ES-Adaptive-Response-Custom-Local-Scripts-using-Dynamic/m-p/676640#M1682</guid>
      <dc:creator>treven</dc:creator>
      <dc:date>2024-02-05T20:15:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES Adaptive Response | Custom Local Scripts using Dynamic Variables to query external APIs</title>
      <link>https://community.splunk.com/t5/Other-Usage/Splunk-ES-Adaptive-Response-Custom-Local-Scripts-using-Dynamic/m-p/683841#M1723</link>
      <description>&lt;P&gt;Did you ever figured this out?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 17:39:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/Splunk-ES-Adaptive-Response-Custom-Local-Scripts-using-Dynamic/m-p/683841#M1723</guid>
      <dc:creator>Albert_Cyber</dc:creator>
      <dc:date>2024-04-10T17:39:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES Adaptive Response | Custom Local Scripts using Dynamic Variables to query external APIs</title>
      <link>https://community.splunk.com/t5/Other-Usage/Splunk-ES-Adaptive-Response-Custom-Local-Scripts-using-Dynamic/m-p/686366#M1733</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/261218"&gt;@Albert_Cyber&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind of, we are in the process of creating custom apps for these use cases and adaptive response actions. The only problem is it really is a pain to create a whole app to just make some very simple api calls and run basic commands like dig against a specified variable. We are following: &lt;A href="https://dev.splunk.com/enterprise/docs/devtools/enterprisesecurity/adaptiveresponseframework/createadaptiveresponseaction" target="_blank"&gt;Create an AR action | Documentation | Splunk Developer Program&lt;/A&gt;&amp;nbsp;the guidance from these docs as there isn't much out there on it and I'm more of a bash scripter than a python programmer so it is a very slow process for us.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2024 17:31:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/Splunk-ES-Adaptive-Response-Custom-Local-Scripts-using-Dynamic/m-p/686366#M1733</guid>
      <dc:creator>treven</dc:creator>
      <dc:date>2024-05-03T17:31:59Z</dc:date>
    </item>
  </channel>
</rss>

