Splunk Enterprise Security

Where is the "Add New Response Action" in enterprise security?

jbender72
Path Finder

Hello,

I must be really tired.  Cannot find the Add New Response Action, which is part of setting up my new ES.  Can anyone help?

jbender72_0-1613775007701.png

Thank You!

Labels (1)
0 Karma
1 Solution

lkutch_splunk
Splunk Employee
Splunk Employee

If you click on a Correlation Search (for example) such as (chosen at random) "ESCU - Detect Windows DNS SIGRed via Splunk Stream - Rule"... you can scroll down to Adaptive Response Actions and click +Add New Response Action.

So that's under Configure -> Content -> Content Management -> <name of correlation search>

View solution in original post

Tags (1)

lkutch_splunk
Splunk Employee
Splunk Employee

If you click on a Correlation Search (for example) such as (chosen at random) "ESCU - Detect Windows DNS SIGRed via Splunk Stream - Rule"... you can scroll down to Adaptive Response Actions and click +Add New Response Action.

So that's under Configure -> Content -> Content Management -> <name of correlation search>

Tags (1)
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...