Splunk Enterprise Security

How do you access notable event IDs from adaptive response Python code?

Path Finder


I have a few adaptive responses (AR) which are tagged to run on correlation rule triggering. These Adaptive responses are working fine and getting the data. Now I want to save this AR data to a KVstore and tagged with an associated notable event ID. My intention is to fetch this data later using the notable event ID field.

However, I can't find any way to access/get the notable event ID from within the adaptive response code. I tried using the helper.get_events() but it doesn't have a notable event ID field. Please let me know if anyone has done this before.


0 Karma

Splunk Employee
Splunk Employee

What notable event id you want to use? Could you please post your codes?

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!