Splunk Enterprise Security

How to Add Workflow Search Action under notable event

gsabhay77
Explorer

From a Splunk custom App, I need to add the workflow action which should be displayed under the Actions menu for the notable event in the Incident Review view in the Splunk Enterprise Security. I have created a workflow action with 'Show Action in' attribute set to 'Event menu' and this workflow action is not visible in the notable event Actions ( in both the search and Incident Review view in the Enterprise Security ) but visible in the search view of the Splunk Enterprise.

0 Karma

diogofgm
SplunkTrust
SplunkTrust

In ES you can setup Adaptive Response Actions that you can either make a correlation search run automatically when its triggered or ru n it your self you want.
In the Incident review dashboard got the the actions column and select "Run Adaptive Response Action"
alt text

And then select whatever action you want use. Some TAs already bring some of these actions and you can make your own.
alt text

NOTE: your workflow actions will still work on a field basis in the incident review dashboard.

More info on Adaptive Response Actions from docs:
https://docs.splunk.com/Documentation/ES/5.3.1/Admin/Setupadaptiveresponse

More info on how to create your own Adaptive Response Action
http://dev.splunk.com/view/enterprise-security/SP-CAAAFBF

------------
Hope I was able to help you. If so, some karma would be appreciated.
0 Karma

gsabhay77
Explorer

Thanks for the info.. Can this be achieved using workflow actions instead of adaptive response actions as I have already have workflow action created for it. If I can only use the adaptive responsive action, can responsive action be created in the Splunk ES from a different Splunk app?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...