Splunk Enterprise Security

Trigger an action manually

alekwisnia
Explorer

I need an action for an incident responder to send a selected event's data via email. I can define notable actions, but they will be triggered automatically when a notable is created. How can I do this manually?

Labels (2)
0 Karma

lakshman239
Influencer

One option would be to create a custom adaptive action (AR), which can be manually invoked by the responder. [ Your AR code would need to then collect the required information from the correlation search/search events and send/email as needed]

0 Karma
Get Updates on the Splunk Community!

Harnessing Splunk’s Federated Search for Amazon S3

Managing your data effectively often means balancing performance, costs, and compliance. Splunk’s Federated ...

Infographic provides the TL;DR for the 2024 Splunk Career Impact Report

We’ve been buzzing with excitement about the recent validation of Splunk Education! The 2024 Splunk Career ...

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...