Splunk Enterprise Security

Adaptive response actions wont show up

reubenjoseph
Explorer

We have created a large amount of custom Adaptive response actions that primarily consist of actions that fetch information from the internet using API calls.

All the apps were created using the latest version of Splunk add-on builder, we have over 12 TA apps at the moment some of them implement up to 4 alert actions.

The problem that we are facing is that while all of these apps are installing correctly and are visible in the Alert actions view, not all the actions are visible in the Enterprise Security drop-down list (While creating a correlation search), only a certain number of actions are visible. Our use case requires multiple adaptive response to actions be executed during notable event creation.

All of these actions (Including the missing entries) can be executed using the sendalert command and passing the parameters manually.

What could be the cause of this? Could it be an app import issue in ES?

0 Karma
1 Solution

scheng_splunk
Splunk Employee
Splunk Employee

There's known ES issue SOLNESS-18523 - Adaptive Response's are being truncated in the correlation search editor page which leads to incomplete results of REST endpoints being displayed.

The fix is implemented in ES version 5.3.1.

View solution in original post

scheng_splunk
Splunk Employee
Splunk Employee

There's known ES issue SOLNESS-18523 - Adaptive Response's are being truncated in the correlation search editor page which leads to incomplete results of REST endpoints being displayed.

The fix is implemented in ES version 5.3.1.

jawahardeen
Engager

In Splunk ESS 5.3.0 -

All the entries (eg: pagerduty, thehive etc.,) shown under Notable->'Recommended Actions' section in the Correlation Search's configuration are not shown in the 'Run Adaptive Response Actions' pop-up (after clicking drop-down on incidents' 'Actions' column) in 'Incident Review' page.

Is this issue also tracked under 'SOLNESS-18523'?

0 Karma

scheng_splunk
Splunk Employee
Splunk Employee

If you run the following two REST endpoint searches:

    | rest splunk_server=local /servicesNS/nobody/SplunkEnterpriseSecuritySuite/alerts/alert_actions | search (is_custom=1
    OR name="email" OR name="script") AND disabled!=1 | table title

and

|rest splunk_server=local /servicesNS/nobody/SplunkEnterpriseSecuritySuite/data/ui/alerts |table title

Do you see more than 30 results?

SOLNESS-18523 is due to the fact we are truncating the results at 30 hence not all the action are visible.

If you have all the entries stop showing assuming it was working previously, i would suggest first try clearing browser and splunkd cache:
https://docs.splunk.com/Documentation/Splunk/latest/AdvancedDev/CustomizationOptions#Clear_client_an...

0 Karma

jawaharas
Motivator

Thanks for your reply. Both of above REST API returns less than 30 records.

Even after clearing browser and splunkd cache, 'Run Adaptive Response Actions' pop-up doesn't show all the 'alert action' entries.

0 Karma

jawaharas
Motivator

Answer to my query -
Adding below config in alert_actions.conf file fix the issue.

[thehive_alert_create_alert]
param._cam = {"supports_adhoc": true}
0 Karma

lakshman239
Influencer

When using add-on builder, i assume you 'ticked' the box to indicate this add-on is to be used in ES as adaptive response action. Also, have you created each of the add-on as with its own name, e.g. TA-addon1, TA-addon2 etc.. so that they can be installed and have unique name [ default/app.conf]

0 Karma
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...