Splunk Enterprise Security

How to invoke adhoc queries

pcyr
Engager

After installing and configuring this application I am unable to get the adaptive response to run. I continue to get teh error as follows:
" "Shodan IP Lookup" could not be dispatched: ModularActionException: Invalid parameter for ad hoc modular action."

Is there a format which is needed when invoking this adaptive response directly from the event and manually placing the IP into the IP lookup field? Thank you.

0 Karma

dperre_splunk
Splunk Employee
Splunk Employee

Hey pcyr. Do you have Splunk Add-on for CIM installed?
Another got you is that you need to go into the index settings and select an index and press save

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...