Splunk Enterprise Security

How do you access notable event IDs from adaptive response Python code?

Path Finder


I have a few adaptive responses (AR) which are tagged to run on correlation rule triggering. These Adaptive responses are working fine and getting the data. Now I want to save this AR data to a KVstore and tagged with an associated notable event ID. My intention is to fetch this data later using the notable event ID field.

However, I can't find any way to access/get the notable event ID from within the adaptive response code. I tried using the helper.get_events() but it doesn't have a notable event ID field. Please let me know if anyone has done this before.


Splunk Employee
Splunk Employee

What notable event id you want to use? Could you please post your codes?

