Splunk Enterprise Security

Bulk manage adaptive response (send email) for Content Management in ES

cachexploit
Explorer

Since I have gone through and tuned a lot of the Content in ES, I am looking to see if anyone knows of a Bulk way to add an Adaptive Response (as in send an email) for every Incident Created?  I am at the point now where things are in a good place and I would not be overwhlemed with the amount of emails that would come in from the Incidents BUT now I want to send an email for every one that is created but I don't want to have to go through Content Management and set an adaptive response for EVERY SINGLE one that is enabled.

For a little more info, I am using Splunk Cloud and ES. so any back end things I would have to submit a ticket to support (which I am not against doing, just want to make sure that is the route I need to go).

TIA

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...