Splunk Enterprise

Can I perform an action in server through Splunk?

Mrig342
Contributor

Hi All,

I want to understand if there is a way to perform an action to the server through Splunk.

For e.g.

  • to run ls -lrt command for a path
  • to kill/terminate a process
  • to run a script on the server etc.

Your kind help will be highly appreciated.

Thank you..!!

Labels (1)
0 Karma
1 Solution

PickleRick
SplunkTrust
SplunkTrust

You could write custom alert actions to perform various tasks but in general it's not something that really should be done by splunk. This is more a SOAR (like Phantom) domain, not Splunk Enterprise.

There would be many caveats to avoid/overcome (like handling credentials) so it's not that straightforward to do. But theoretically - yes, you can do "anything" using custom actions. As long as you can script it.

Mrig342
Contributor

Thank you @PickleRick 

Can you help me with some splunk documents to go through on this topic to explore.

Your help is much appreciated..!!

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...