Hi All,
I want to understand if there is a way to perform an action to the server through Splunk.
For e.g.
Your kind help will be highly appreciated.
Thank you..!!
You could write custom alert actions to perform various tasks but in general it's not something that really should be done by splunk. This is more a SOAR (like Phantom) domain, not Splunk Enterprise.
There would be many caveats to avoid/overcome (like handling credentials) so it's not that straightforward to do. But theoretically - yes, you can do "anything" using custom actions. As long as you can script it.
Thank you @PickleRick
Can you help me with some splunk documents to go through on this topic to explore.
Your help is much appreciated..!!