Splunk Enterprise Security

The "Run Adaptive Response Actions" is not listing all the alert actions in Splunk where while editing the correlation searches the options are available under "Adaptive Response Actions"

Splunk Employee
Splunk Employee

Description:
1. I have installed TA-thehive & TA-PagerDuty on Splunk ES search head.
2. While editing the correlation searches I am getting these apps alert options under Adaptive Response Actions. But in incident review panel when I am trying to add the "run adaptive response action" I am getting only the default alert actions, not the hive and PagerDuty.

Architecture: ES v 5.3.1 | Splunk v 7.3.1

Reproduction steps:
1. Install TA-thehive (https://splunkbase.splunk.com/app/4380/) & PagerDuty Addon (https://splunkbase.splunk.com/app/3742/) on ES search head.
2. Edit the correlation search and check for the Adaptive Response Actions, you will see the the-hive & pagerduty as an alert action.
3. Go to the incident review panel. Click "Action" in front of any notable and select "run adaptive response action". the-hive and pagerduty options are not available.

Note:
I suspect this issue might be related to App version compatibility. Meaning,

Splunk ES 5.3.1 is compatible with Splunk Versions: 7.3, 7.2, 7.1
PagerDuty Addon is compatible with Splunk Versions: 7.0, 6.6, 6.5, 6.4, 6.3
TA-thehive Addon is compatible with Splunk Versions: 7.2, 7.1, 7.0, 6.6 **

Screenshots:
1. While editing the correlation search:
alt text

  1. Notable > Action: alt text

Could you please confirm whether this is a default behavior? Or due to version compatibility?

0 Karma
1 Solution

Splunk Employee
Splunk Employee

"This is as Designed" if you don't have param.cam defined for your alert action. Also, the Incident Review requires that you have "supportsadhoc" set to true.

To Resolve:

$Splunk_Home/etc/apps/TA-thehive/default

[thehivealertcreatealert]
is
custom = 1
label = create THEHIVE alert(s) (alert action)
description = Create alerts in theHive
iconpath = thehivelogosmall.png
payload
format = json
disabled = 0

Note, that the action is named "thehivealertcreatealert", and has no param.cam definition. I verified this does not show up on Incident Review.
Next, all I did was add a simple param._cam definition:

[thehivealertcreatealert]
is
custom = 1
label = create THEHIVE alert(s) (alert action)
description = Create alerts in theHive
iconpath = thehivelogosmall.png
payload
format = json
disabled = 0
param.cam = {"supportsadhoc": true}

Note:Make the changes in $SplunkHome/etc/apps/appname/local

View solution in original post

0 Karma

Splunk Employee
Splunk Employee

"This is as Designed" if you don't have param.cam defined for your alert action. Also, the Incident Review requires that you have "supportsadhoc" set to true.

To Resolve:

$Splunk_Home/etc/apps/TA-thehive/default

[thehivealertcreatealert]
is
custom = 1
label = create THEHIVE alert(s) (alert action)
description = Create alerts in theHive
iconpath = thehivelogosmall.png
payload
format = json
disabled = 0

Note, that the action is named "thehivealertcreatealert", and has no param.cam definition. I verified this does not show up on Incident Review.
Next, all I did was add a simple param._cam definition:

[thehivealertcreatealert]
is
custom = 1
label = create THEHIVE alert(s) (alert action)
description = Create alerts in theHive
iconpath = thehivelogosmall.png
payload
format = json
disabled = 0
param.cam = {"supportsadhoc": true}

Note:Make the changes in $SplunkHome/etc/apps/appname/local

View solution in original post

0 Karma