Splunk Enterprise Security

How can I achieve a field validation in a Custom Adaptive Response Action?

nicolociraci
New Member

Hello,

I'm unable to get field validation in a Custom Adaptive Response Action in Splunk Enterprise Security. What I would like to achieve is a field validation that obliges the user to fill the field (required field) but I can't get even the simplest validation working. When I click on the run button in the adaptive actions modal view on the incident, I get no validation but a message saying "action has been dispatched".

Furthermore which field should I put in alert_actions.conf.spec and savedsearched.conf.spec? The documentation I have read is quite vague.

Thanks!

0 Karma
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...