Splunk Enterprise Security

Enterprise Security connect to firewall and block IP addresses?

johnny_goya
Explorer

Hi guys,

There is a way that i can automate block IP addresses in my firewall with a script?

Where can i put my script and how can i execute?

I was trying to use adaptive response, i'm in the right direction?

0 Karma
1 Solution

tiagofbmm
Influencer

Put the script on the bin directory of the app you have to wrap it, and create a custom adaptive response that will take it. Make sure Splunk will have permissions to execute such operations at OS level... which may no be possible

View solution in original post

0 Karma

tiagofbmm
Influencer

Put the script on the bin directory of the app you have to wrap it, and create a custom adaptive response that will take it. Make sure Splunk will have permissions to execute such operations at OS level... which may no be possible

0 Karma

tiagofbmm
Influencer

@johnny_goya please accept an answer if it solved/helped it and upvote it. Otherwise let us know how can we help further

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...