<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do you create an Adaptive Response action using Python Script? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-you-create-an-Adaptive-Response-action-using-Python/m-p/652585#M11642</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/259169"&gt;@WillBryant&lt;/a&gt;, Have you checked -&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://dev.splunk.com/enterprise/docs/devtools/enterprisesecurity/adaptiveresponseframework/exampleadaptiveresponse/" target="_blank"&gt;https://dev.splunk.com/enterprise/docs/devtools/enterprisesecurity/adaptiveresponseframework/exampleadaptiveresponse/&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://www.youtube.com/watch?v=OT11XMB8Bu0" target="_blank"&gt;https://www.youtube.com/watch?v=OT11XMB8Bu0&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
    <pubDate>Mon, 31 Jul 2023 20:01:04 GMT</pubDate>
    <dc:creator>meetmshah</dc:creator>
    <dc:date>2023-07-31T20:01:04Z</dc:date>
    <item>
      <title>How do you create an Adaptive Response action using Python Script?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-you-create-an-Adaptive-Response-action-using-Python/m-p/652418#M11641</link>
      <description>&lt;P&gt;&lt;BR /&gt;I'm trying to run a Python script as part of an Adaptive Response Action.&amp;nbsp; In Splunk ES, I go to Enterprise Security &amp;gt; Configure &amp;gt; Content &amp;gt; Content Management &amp;gt; Correlation Search .&lt;BR /&gt;Under Correlation Search, I added Adaptive Response Actions and selected Run a Script (I was initially told to use Webhook; however I wasn’t able to pass arguments from code—just a parameter for an URL) placed a copy of the Python script that contain the POST request and some exception handling in $Splunk_Home/bin/scripts.&lt;/P&gt;&lt;P&gt;For the Trigger Condition, I selected custom as I wanted to launch the action on demand; however, I’m not sure what parameters to use for this.&amp;nbsp; &amp;nbsp;I tried to find documentation to no avail.&amp;nbsp; Could someone please advise.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 20:30:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-you-create-an-Adaptive-Response-action-using-Python/m-p/652418#M11641</guid>
      <dc:creator>WillBryant</dc:creator>
      <dc:date>2023-07-28T20:30:53Z</dc:date>
    </item>
    <item>
      <title>Re: How do you create an Adaptive Response action using Python Script?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-you-create-an-Adaptive-Response-action-using-Python/m-p/652585#M11642</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/259169"&gt;@WillBryant&lt;/a&gt;, Have you checked -&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://dev.splunk.com/enterprise/docs/devtools/enterprisesecurity/adaptiveresponseframework/exampleadaptiveresponse/" target="_blank"&gt;https://dev.splunk.com/enterprise/docs/devtools/enterprisesecurity/adaptiveresponseframework/exampleadaptiveresponse/&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://www.youtube.com/watch?v=OT11XMB8Bu0" target="_blank"&gt;https://www.youtube.com/watch?v=OT11XMB8Bu0&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Mon, 31 Jul 2023 20:01:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-you-create-an-Adaptive-Response-action-using-Python/m-p/652585#M11642</guid>
      <dc:creator>meetmshah</dc:creator>
      <dc:date>2023-07-31T20:01:04Z</dc:date>
    </item>
  </channel>
</rss>

