Hi All,
I have a requirement to send alert result to Cortex ( Third Party System ).
I am thinking of running a custom script on alert action.
Can anyone suggest how should I proceed further.
Start here: https://docs.splunk.com/Documentation/Splunk/8.1.0/AdvancedDev/CustomAlertScript