Other Usage

Splunk ES Adaptive Response | Custom Local Scripts using Dynamic Variables to query external APIs

treven
Explorer

Hey Everyone!

We just started using Splunk ES, we just got it up and running fairly well and I have a couple questions hopefully I could get some guidance on or maybe a point in the right direction. I would like to somehow setup the ability for analyst to be able to run local scripts in the adaptive response that use dynamic user input as variables to query external APIs. Another scenario, I was hoping we could use, would be using specific tokens/fields as the dynamic variable for these scripts and just give the analyst the output in the adaptive response when they are ran. Are any of these scenarios possible with ES we have tried to find a way to do this but so far have not come up with any successful implementation. Is there any documentation on implementing something like this? Any help would be very much appreciated!

Tags (1)
0 Karma

Albert_Cyber
Explorer

Did you ever figured this out? 

0 Karma

treven
Explorer

@Albert_Cyber , 

 

Kind of, we are in the process of creating custom apps for these use cases and adaptive response actions. The only problem is it really is a pain to create a whole app to just make some very simple api calls and run basic commands like dig against a specified variable. We are following: Create an AR action | Documentation | Splunk Developer Program the guidance from these docs as there isn't much out there on it and I'm more of a bash scripter than a python programmer so it is a very slow process for us. 

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...