Splunk Enterprise

Is it possible to run a Script From Splunk on Remote Server?

SanjayReddy
SplunkTrust
SplunkTrust

Hi Team,

We have a requirement where we need to run script on remote server based on search condition from Splunk

Example, from search results, found that for 10 servers, windows service is down, 
as a part of alert condition Splunk need to login into the remote server and start the service using script

wanted to check can this be done?.

any leads to related to recourses will be helpful 


 

 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

That is exactly what Splunk SOAR is for.

Splunk Enterprise lets you run a script when an alert is triggered, but that feature has been deprecated for a while.  It should still work, however.  Note that the script runs on the local Splunk server.  It's up to the you and the script to get something running on the remote server.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...