I was trying to get started with Splunk Adaptive Response framework setup and came across 'Ember', I dont understand what ember is, why we need it and how to setup, it would be helpful if you provide any documentation relating to ember.
Thanks for clarifying. The prototype app that you are using is misleading and out of date.
The adaptive response framework is now generally available in Splunk Enterprise Security version 4.5.0. You can install the (free) Common Information Model to access the tooling that will help you build your own adaptive response actions, or use Add-on Builder (also free), which offers a helpful UI.
Read more about adaptive response here: http://dev.splunk.com/view/enterprise-security/SP-CAAAFBE
Hi Druuu,
Ember is an internal name for a Splunk Enterprise release, several releases ago. Can you tell us where you came across that, so we can fix it?
Thanks,
~ Robin
I get the above page when trying to setup splunk adaptive response framework. So how do i run ember with modular alerts capability?
The image has got broken! please refer to http://www.imageno.com/7y4dyrfaopx0pic.html