Splunk Enterprise Security

How can I achieve a field validation in a Custom Adaptive Response Action?

nicolociraci
New Member

Hello,

I'm unable to get field validation in a Custom Adaptive Response Action in Splunk Enterprise Security. What I would like to achieve is a field validation that obliges the user to fill the field (required field) but I can't get even the simplest validation working. When I click on the run button in the adaptive actions modal view on the incident, I get no validation but a message saying "action has been dispatched".

Furthermore which field should I put in alert_actions.conf.spec and savedsearched.conf.spec? The documentation I have read is quite vague.

Thanks!

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...