Splunk Enterprise Security

Custom Adaptive Response Invocations Result Manuel

burakatabay
Path Finder

Hi,
I create own custom adaptive response action. This adhoc action is worked.
But, I don't use cim_action.py lib on my script.py . script is worked but invocation result not showing.
Also, My adaptive response action result not writing .

How can I do this without using cim_action.py ? OR Can I do it ?
For example ? I run my adhoc adaptive response and .

alt text

0 Karma

lakshman239
Influencer

To my understanding, only Adaptive Actions (AR) written to work within the 'CIM modactions' framework will appear under the 'Adaptive Responses' pane of the incident review dashboard. You could use the Add-on builder (if not using already) to create your custom AR and that could address your need to view/list your AR

0 Karma
Get Updates on the Splunk Community!

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...

Explore the Latest Educational Offerings from Splunk (November Releases)

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...