<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Adaptive response actions wont show up in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Adaptive-response-actions-wont-show-up/m-p/417392#M5066</link>
    <description>&lt;P&gt;Answer to my query -&lt;BR /&gt;
Adding below config in &lt;CODE&gt;alert_actions.conf&lt;/CODE&gt; file fix the issue.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[thehive_alert_create_alert]
param._cam = {"supports_adhoc": true}
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 10 Sep 2019 00:41:59 GMT</pubDate>
    <dc:creator>jawaharas</dc:creator>
    <dc:date>2019-09-10T00:41:59Z</dc:date>
    <item>
      <title>Adaptive response actions wont show up</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Adaptive-response-actions-wont-show-up/m-p/417386#M5060</link>
      <description>&lt;P&gt;We have created a large amount of custom Adaptive response actions that primarily consist of actions that fetch information from the internet using API calls.&lt;/P&gt;

&lt;P&gt;All the apps were created using the latest version of Splunk add-on builder, we have over 12 TA apps at the moment some of them implement up to 4 alert actions.&lt;/P&gt;

&lt;P&gt;The problem that we are facing is that while all of these apps are installing correctly and are visible in the Alert actions view, not all the actions are visible in the Enterprise Security drop-down list (While creating a correlation search), only a certain number of actions are visible. Our use case requires multiple adaptive response to actions be executed during notable event creation.&lt;/P&gt;

&lt;P&gt;All of these actions (Including the missing entries) can be executed using the &lt;CODE&gt;sendalert&lt;/CODE&gt; command and passing the parameters manually.&lt;/P&gt;

&lt;P&gt;What could be the cause of this? Could it be an app import issue in ES?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Dec 2018 01:47:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Adaptive-response-actions-wont-show-up/m-p/417386#M5060</guid>
      <dc:creator>reubenjoseph</dc:creator>
      <dc:date>2018-12-03T01:47:34Z</dc:date>
    </item>
    <item>
      <title>Re: Adaptive response actions wont show up</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Adaptive-response-actions-wont-show-up/m-p/417387#M5061</link>
      <description>&lt;P&gt;When using add-on builder, i assume you 'ticked' the box to indicate this add-on is to be used in ES as adaptive response action.  Also, have you created each of the add-on as with its own name, e.g. TA-addon1, TA-addon2 etc.. so that they can be installed and have unique name [ default/app.conf]&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jan 2019 16:48:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Adaptive-response-actions-wont-show-up/m-p/417387#M5061</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-01-11T16:48:36Z</dc:date>
    </item>
    <item>
      <title>Re: Adaptive response actions wont show up</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Adaptive-response-actions-wont-show-up/m-p/417388#M5062</link>
      <description>&lt;P&gt;There's known ES issue SOLNESS-18523 - Adaptive Response's are being truncated in the correlation search editor page which leads to incomplete results of REST endpoints being displayed.&lt;/P&gt;

&lt;P&gt;The fix is implemented in ES version 5.3.1.&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2019 01:49:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Adaptive-response-actions-wont-show-up/m-p/417388#M5062</guid>
      <dc:creator>scheng_splunk</dc:creator>
      <dc:date>2019-05-08T01:49:05Z</dc:date>
    </item>
    <item>
      <title>Re: Adaptive response actions wont show up</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Adaptive-response-actions-wont-show-up/m-p/417389#M5063</link>
      <description>&lt;P&gt;In Splunk ESS &lt;STRONG&gt;5.3.0&lt;/STRONG&gt; -&lt;/P&gt;

&lt;P&gt;All the entries (eg: pagerduty, thehive etc.,) shown under &lt;EM&gt;Notable-&amp;gt;'Recommended Actions'&lt;/EM&gt; section in the Correlation Search's configuration are not shown in the &lt;EM&gt;'Run Adaptive Response Actions'&lt;/EM&gt; pop-up (after clicking drop-down on incidents' 'Actions' column) in 'Incident Review' page. &lt;/P&gt;

&lt;P&gt;Is this issue also tracked under 'SOLNESS-18523'? &lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2019 05:08:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Adaptive-response-actions-wont-show-up/m-p/417389#M5063</guid>
      <dc:creator>jawahardeen</dc:creator>
      <dc:date>2019-06-27T05:08:24Z</dc:date>
    </item>
    <item>
      <title>Re: Adaptive response actions wont show up</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Adaptive-response-actions-wont-show-up/m-p/417390#M5064</link>
      <description>&lt;P&gt;If you run the following two REST endpoint searches:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    | rest splunk_server=local /servicesNS/nobody/SplunkEnterpriseSecuritySuite/alerts/alert_actions | search (is_custom=1
    OR name="email" OR name="script") AND disabled!=1 | table title
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;and&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;|rest splunk_server=local /servicesNS/nobody/SplunkEnterpriseSecuritySuite/data/ui/alerts |table title
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Do you see more than 30 results?&lt;/P&gt;

&lt;P&gt;SOLNESS-18523 is due to the fact we are truncating the results at 30 hence not all the action are visible.&lt;/P&gt;

&lt;P&gt;If you have all the entries stop showing assuming it was working previously, i would suggest first try clearing browser and splunkd cache:&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/AdvancedDev/CustomizationOptions#Clear_client_and_server_assets_caches_after_customization"&gt;https://docs.splunk.com/Documentation/Splunk/latest/AdvancedDev/CustomizationOptions#Clear_client_and_server_assets_caches_after_customization&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2019 06:15:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Adaptive-response-actions-wont-show-up/m-p/417390#M5064</guid>
      <dc:creator>scheng_splunk</dc:creator>
      <dc:date>2019-06-27T06:15:05Z</dc:date>
    </item>
    <item>
      <title>Re: Adaptive response actions wont show up</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Adaptive-response-actions-wont-show-up/m-p/417391#M5065</link>
      <description>&lt;P&gt;Thanks for your reply. Both of above REST API returns less than 30 records. &lt;/P&gt;

&lt;P&gt;Even after clearing browser and splunkd cache, 'Run Adaptive Response Actions' pop-up doesn't show all the 'alert action' entries. &lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2019 06:26:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Adaptive-response-actions-wont-show-up/m-p/417391#M5065</guid>
      <dc:creator>jawaharas</dc:creator>
      <dc:date>2019-06-27T06:26:12Z</dc:date>
    </item>
    <item>
      <title>Re: Adaptive response actions wont show up</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Adaptive-response-actions-wont-show-up/m-p/417392#M5066</link>
      <description>&lt;P&gt;Answer to my query -&lt;BR /&gt;
Adding below config in &lt;CODE&gt;alert_actions.conf&lt;/CODE&gt; file fix the issue.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[thehive_alert_create_alert]
param._cam = {"supports_adhoc": true}
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 10 Sep 2019 00:41:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Adaptive-response-actions-wont-show-up/m-p/417392#M5066</guid>
      <dc:creator>jawaharas</dc:creator>
      <dc:date>2019-09-10T00:41:59Z</dc:date>
    </item>
  </channel>
</rss>

