Splunk SOAR

Is there a way to automatically trigger SOAR playbook from S3 file added event?

akitatake
New Member

Hello,

Is there a way to have a playbook automatically trigger when a file is added to an S3 bucket in our AWS account? My initial thought is to have an AWS lambda trigger when a file is added to the S3 bucket, then have that lambda publish the file event information to a kafka topic, then have our Splunk SOAR hooked up to poll that kafka topic via the Kafka SOAR App, then have the playbook set up to trigger when something comes in on that poll (if that's even possible). Is this the best way to go about this?

Thank you!

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...