<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk ES - Adaptive Response - Send Email per Result of Correlation Search in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Adaptive-Response-Send-Email-per-Result-of-Correlation/m-p/433401#M5688</link>
    <description>&lt;P&gt;Lets say you have a field called myemail_addr in each of the 5 events, resulting from your correlation search, you can use that as a token $myemail_address$ in the email adaptive response to send different email to each of the 5 users. would this help?&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 22:41:35 GMT</pubDate>
    <dc:creator>lakshman239</dc:creator>
    <dc:date>2020-09-29T22:41:35Z</dc:date>
    <item>
      <title>Splunk ES - Adaptive Response - Send Email per Result of Correlation Search</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Adaptive-Response-Send-Email-per-Result-of-Correlation/m-p/433400#M5687</link>
      <description>&lt;P&gt;Hey Team,&lt;/P&gt;

&lt;P&gt;Wanted to be able to send an email as an Adaptive Response for a correlation search per result. Just like a notable event is created per-event, is there a way to configure the "Send Email" to be sent per-event, based on information in the notable event?&lt;/P&gt;

&lt;P&gt;For example, if a correlation search has 5 hits, 5 notable events are created. Let's say there are 5 different email addresses on these 5 events; is it possible to use "$result.email$" to alter who get the email per event?&lt;/P&gt;

&lt;P&gt;I know a limitation or the design of $result.email$ is just to take the first row, but was thinking when used in conjunction with Correlation search, there might be a way to utilize the Adaptive Response per event.&lt;/P&gt;

&lt;P&gt;Thoughts? Any additional data needed? Thanks all!&lt;/P&gt;</description>
      <pubDate>Mon, 10 Dec 2018 22:38:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Adaptive-Response-Send-Email-per-Result-of-Correlation/m-p/433400#M5687</guid>
      <dc:creator>gworkun</dc:creator>
      <dc:date>2018-12-10T22:38:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES - Adaptive Response - Send Email per Result of Correlation Search</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Adaptive-Response-Send-Email-per-Result-of-Correlation/m-p/433401#M5688</link>
      <description>&lt;P&gt;Lets say you have a field called myemail_addr in each of the 5 events, resulting from your correlation search, you can use that as a token $myemail_address$ in the email adaptive response to send different email to each of the 5 users. would this help?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:41:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Adaptive-Response-Send-Email-per-Result-of-Correlation/m-p/433401#M5688</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2020-09-29T22:41:35Z</dc:date>
    </item>
  </channel>
</rss>

