Splunk Enterprise Security

How to invoke adhoc queries

pcyr
Engager

After installing and configuring this application I am unable to get the adaptive response to run. I continue to get teh error as follows:
" "Shodan IP Lookup" could not be dispatched: ModularActionException: Invalid parameter for ad hoc modular action."

Is there a format which is needed when invoking this adaptive response directly from the event and manually placing the IP into the IP lookup field? Thank you.

0 Karma

dperre_splunk
Splunk Employee
Splunk Employee

Hey pcyr. Do you have Splunk Add-on for CIM installed?
Another got you is that you need to go into the index settings and select an index and press save

0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Cloud Platform 9.3.2411?

Hey Splunky People! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2411. This release ...

Buttercup Games: Further Dashboarding Techniques (Part 6)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...