Splunk Enterprise Security

How can I write my own adaptive response action?

smoir_splunk
Splunk Employee
Splunk Employee

I want to build an adaptive response action to push malware signatures from Enterprise Security into my own application and return data about them to ES using a REST API. What is the best way to get started? Are there any examples?

0 Karma
1 Solution

rpille_splunk
Splunk Employee
Splunk Employee

Yes, we have documentation and examples that walk through building a custom adaptive response action.

Follow this documentation for step-by-step instructions: http://dev.splunk.com/view/enterprise-security/SP-CAAAFBF

You'll notice there are two paths available to you:
1. Use Splunk Add-on Builder, which simplifies the process considerably. See this example: http://dev.splunk.com/view/addon-builder/SP-CAAAFBQ
2. Create the action manually. See this example: http://dev.splunk.com/view/enterprise-security/SP-CAAAFBH

If you want to use Splunk Add-on Builder, download it here: https://splunkbase.splunk.com/app/2962/

View solution in original post

rpille_splunk
Splunk Employee
Splunk Employee

Yes, we have documentation and examples that walk through building a custom adaptive response action.

Follow this documentation for step-by-step instructions: http://dev.splunk.com/view/enterprise-security/SP-CAAAFBF

You'll notice there are two paths available to you:
1. Use Splunk Add-on Builder, which simplifies the process considerably. See this example: http://dev.splunk.com/view/addon-builder/SP-CAAAFBQ
2. Create the action manually. See this example: http://dev.splunk.com/view/enterprise-security/SP-CAAAFBH

If you want to use Splunk Add-on Builder, download it here: https://splunkbase.splunk.com/app/2962/

First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...