Splunk SOAR

Is there a way to automatically trigger SOAR playbook from S3 file added event?

akitatake
New Member

Hello,

Is there a way to have a playbook automatically trigger when a file is added to an S3 bucket in our AWS account? My initial thought is to have an AWS lambda trigger when a file is added to the S3 bucket, then have that lambda publish the file event information to a kafka topic, then have our Splunk SOAR hooked up to poll that kafka topic via the Kafka SOAR App, then have the playbook set up to trigger when something comes in on that poll (if that's even possible). Is this the best way to go about this?

Thank you!

Labels (2)
0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...