Hello, I want to use SOAR with Splunk Enterprise. The two work together so that I do not buy Splunk ES. Therefore, I want the process to be automatic. I take data from SplunkEnterprise to the soar, and the soar performs the actin processes. How is this done? Note: I was using splunk ES, but the process is cumbersome on the one hand. Resources
You could use Splunk App for SOAR Export | Splunkbase to send events to Splunk SOAR
question in the educational clips explains that an alert is generated from splunk and sent to soar this process is cumbersome I want to have soar to make action for gifts without creating an alert i mean the process is automatic