Splunk Enterprise Security

Where is the "Add New Response Action" in enterprise security?

jbender72
Path Finder

Hello,

I must be really tired.  Cannot find the Add New Response Action, which is part of setting up my new ES.  Can anyone help?

jbender72_0-1613775007701.png

Thank You!

Labels (1)
0 Karma
1 Solution

lkutch_splunk
Splunk Employee
Splunk Employee

If you click on a Correlation Search (for example) such as (chosen at random) "ESCU - Detect Windows DNS SIGRed via Splunk Stream - Rule"... you can scroll down to Adaptive Response Actions and click +Add New Response Action.

So that's under Configure -> Content -> Content Management -> <name of correlation search>

View solution in original post

Tags (1)

lkutch_splunk
Splunk Employee
Splunk Employee

If you click on a Correlation Search (for example) such as (chosen at random) "ESCU - Detect Windows DNS SIGRed via Splunk Stream - Rule"... you can scroll down to Adaptive Response Actions and click +Add New Response Action.

So that's under Configure -> Content -> Content Management -> <name of correlation search>

Tags (1)
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...