Splunk Enterprise

Is it possible to run a Script From Splunk on Remote Server?

SanjayReddy
SplunkTrust
SplunkTrust

Hi Team,

We have a requirement where we need to run script on remote server based on search condition from Splunk

Example, from search results, found that for 10 servers, windows service is down, 
as a part of alert condition Splunk need to login into the remote server and start the service using script

wanted to check can this be done?.

any leads to related to recourses will be helpful 


 

 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

That is exactly what Splunk SOAR is for.

Splunk Enterprise lets you run a script when an alert is triggered, but that feature has been deprecated for a while.  It should still work, however.  Note that the script runs on the local Splunk server.  It's up to the you and the script to get something running on the remote server.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...