Security & the Enterprise
Much secured. So patch!

Send notable event variables to external REST API.

deovratdeshmukh
Loves-to-Learn

I want to send parameters from ES notable events to external SOAR (not Phantom) REST. Is there any addon available or the addon has to be developed. If addon needs to be developed, if there is any readily available framework to develop it quickly.

0 Karma

anm_mporter
Explorer

Does your SOAR REST API accept a simple POST? Perhaps with an authtoken in the URL? then you can use the Webhook alert action to POST the results of a search to that url

 

Otherwise you are looking at a custom alert action. 

0 Karma
Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...