Security & the Enterprise
Much secured. So patch!

Splunk as IPS

vmicovic2
Explorer

Hi all,

is there case where someone setup splunk as IPS maybe?

For example, on alert X trigger script which will take from alert IP/MAC and same script will block or change VLAN police of that IP/MAC on ASA for example?

 

 

thank you

0 Karma

vmicovic2
Explorer

ok, does community edition include isolation ?

i need only that option, wont buy whole product for one thing..

0 Karma

richgalloway
SplunkTrust
SplunkTrust

That sounds like the kind of use case for which Splunk has Phantom.

---
If this reply helps you, Karma would be appreciated.

hevertonkleidso
Engager

I would say the same.

0 Karma

hevertonkleidso
Engager

But you don't need to buy a new product. You can use the free version and create some python scripts by your self.

0 Karma

vmicovic2
Explorer

amm.. in that case will create same script which will be triggered on alert X. Don`t need to add another service for simple task..

i was just asking for some experience regarding to subject...

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...