<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using Splunk as a real-time event detection engine in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Using-Splunk-as-a-real-time-event-detection-engine/m-p/24221#M177507</link>
    <description>&lt;P&gt;Sorry reading it on my phone, overlooked the actual question. Yes that should be no problem. You can script with pretty much anything. I generally use python or bash but to each his/her own. :). We often use external alerting to send an ip to a firewall to be dropped or to update a blacklist, etc. Same principle. &lt;/P&gt;</description>
    <pubDate>Mon, 05 Aug 2013 01:30:31 GMT</pubDate>
    <dc:creator>billford</dc:creator>
    <dc:date>2013-08-05T01:30:31Z</dc:date>
    <item>
      <title>Using Splunk as a real-time event detection engine</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-Splunk-as-a-real-time-event-detection-engine/m-p/24218#M177504</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have a requirement for an event detection engine which is able to identify a string (e.g. username) in a particular data source and 'notify' other systems that the event has occurred.&lt;/P&gt;

&lt;P&gt;I appreciate the inherent flexibility Splunk has by allowing Scripts to be used in conjunction with Alerts to achive this, but i wanted to see if anyone is using Splunk within a large enterprise Production environment as an event detection engine (instead of just a data visualisation tool)?&lt;/P&gt;

&lt;P&gt;Once the event has occurred, Splunk will need to 'notify' other systems by sending a JMS message to one system and updating a database table in another system. How suitable is the scripting capability in Splunk for run-time requirements like this?&lt;/P&gt;

&lt;P&gt;Cheers, &lt;BR /&gt;
James.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2013 01:10:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-Splunk-as-a-real-time-event-detection-engine/m-p/24218#M177504</guid>
      <dc:creator>jsash1</dc:creator>
      <dc:date>2013-08-05T01:10:47Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk as a real-time event detection engine</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-Splunk-as-a-real-time-event-detection-engine/m-p/24219#M177505</link>
      <description>&lt;P&gt;Yes. All the time. What is your specific question? &lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2013 01:24:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-Splunk-as-a-real-time-event-detection-engine/m-p/24219#M177505</guid>
      <dc:creator>billford</dc:creator>
      <dc:date>2013-08-05T01:24:07Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk as a real-time event detection engine</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-Splunk-as-a-real-time-event-detection-engine/m-p/24220#M177506</link>
      <description>&lt;P&gt;Once the event has occurred, Splunk will need to 'notify' other systems by sending a JMS message to one system and updating a database table in another system. How suitable is the scripting capability in Splunk for run-time requirements like this?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2013 01:26:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-Splunk-as-a-real-time-event-detection-engine/m-p/24220#M177506</guid>
      <dc:creator>jsash1</dc:creator>
      <dc:date>2013-08-05T01:26:15Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk as a real-time event detection engine</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-Splunk-as-a-real-time-event-detection-engine/m-p/24221#M177507</link>
      <description>&lt;P&gt;Sorry reading it on my phone, overlooked the actual question. Yes that should be no problem. You can script with pretty much anything. I generally use python or bash but to each his/her own. :). We often use external alerting to send an ip to a firewall to be dropped or to update a blacklist, etc. Same principle. &lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2013 01:30:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-Splunk-as-a-real-time-event-detection-engine/m-p/24221#M177507</guid>
      <dc:creator>billford</dc:creator>
      <dc:date>2013-08-05T01:30:31Z</dc:date>
    </item>
  </channel>
</rss>

