Building for the Splunk Platform

Adaptive Response Action - can we set a status of warning?

hughkelley
Path Finder

I have an Adaptive Response Action (execute_flow in the pic below)  that requires certain identity data about the subject of the notable (mobile phone number).   Not all users have a mobile number set in ES identity.

Currently,  I throw a failure event in Python for this condition.   Is it possible to return a warning status instead?

hughkelley_0-1664725084304.png

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

New Learning Videos on Topics Most Requested by You! Plus This Month’s New Splunk ...

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

How I Instrumented a Rust Application Without Knowing Rust

As a technical writer, I often have to edit or create code snippets for Splunk's distributions of ...