Splunk Enterprise Security

How do you access notable event IDs from adaptive response Python code?

ramesh_babu71
Path Finder

Hi,

I have a few adaptive responses (AR) which are tagged to run on correlation rule triggering. These Adaptive responses are working fine and getting the data. Now I want to save this AR data to a KVstore and tagged with an associated notable event ID. My intention is to fetch this data later using the notable event ID field.

However, I can't find any way to access/get the notable event ID from within the adaptive response code. I tried using the helper.get_events() but it doesn't have a notable event ID field. Please let me know if anyone has done this before.

Regards,
Ramesh

0 Karma

chli_splunk
Splunk Employee
Splunk Employee

What notable event id you want to use? Could you please post your codes?

0 Karma
Get Updates on the Splunk Community!

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...

The Great Resilience Quest: 10th Leaderboard Update

The tenth leaderboard update (11.23-12.05) for The Great Resilience Quest is out >> As our brave ...