Splunk Enterprise Security

Trigger an action manually


I need an action for an incident responder to send a selected event's data via email. I can define notable actions, but they will be triggered automatically when a notable is created. How can I do this manually?

One option would be to create a custom adaptive action (AR), which can be manually invoked by the responder. [ Your AR code would need to then collect the required information from the correlation search/search events and send/email as needed]

