Splunk Enterprise

Is it possible to run a Script From Splunk on Remote Server?

SanjayReddy
SplunkTrust
SplunkTrust

Hi Team,

We have a requirement where we need to run script on remote server based on search condition from Splunk

Example, from search results, found that for 10 servers, windows service is down, 
as a part of alert condition Splunk need to login into the remote server and start the service using script

wanted to check can this be done?.

any leads to related to recourses will be helpful 


 

 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

That is exactly what Splunk SOAR is for.

Splunk Enterprise lets you run a script when an alert is triggered, but that feature has been deprecated for a while.  It should still work, however.  Note that the script runs on the local Splunk server.  It's up to the you and the script to get something running on the remote server.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...