Splunk Enterprise Security

Is there a way to run a search with an adaptive response?

justinw
Explorer

I am currently in the process of creating an adaptive response that I want to be able to add some user input into a lookup.

I have the functionality with dashboards/searches currently and would like to use the same searches within the adaptive response. The searches do not take long to run as they are mostly lookup-based. All I need to do is to pass the users input into the code, which I have, and then call those variables within a search, like a dashboard would do with $var$. I would rather do this than change the entire framework to be event based, and create events with the adaptive response.

Is there any way of running a search in/with the adaptive response?

0 Karma

treven
Explorer

This is a pretty old post but were you ever able to figure out a solution to this? I am currently exploring these options with a custom adaptive response.

 

Thanks!

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...