Splunk Enterprise

Is it possible to run a Script From Splunk on Remote Server?

SanjayReddy
SplunkTrust
SplunkTrust

Hi Team,

We have a requirement where we need to run script on remote server based on search condition from Splunk

Example, from search results, found that for 10 servers, windows service is down, 
as a part of alert condition Splunk need to login into the remote server and start the service using script

wanted to check can this be done?.

any leads to related to recourses will be helpful 


 

 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

That is exactly what Splunk SOAR is for.

Splunk Enterprise lets you run a script when an alert is triggered, but that feature has been deprecated for a while.  It should still work, however.  Note that the script runs on the local Splunk server.  It's up to the you and the script to get something running on the remote server.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...