Mars Alert Forwarding Add-on

Splunk Community

Mars Alert Forwarding Add-on

Mars Alert Forwarding Add-on
Mars Alert Forwarding adds a 'Send to Mars' custom alert action that forwards a triggered saved search's results directly to the Mars Security platform in a single outbound delivery. The problem it solves: security teams using Mars for AI-driven threat hunting and detection engineering need their Splunk detections to flow into Mars without manual exporting, copy-pasting results, or building and maintaining custom webhook scripts. This add-on bridges that gap with a simple, native alert action. How it works: - Add 'Send to Mars' to any saved search under Trigger Actions. When the alert fires, the add-on sends the matching results, the SPL behind the search, the configured severity, and key search metadata to your Mars webhook. - Splunk severity (1–5) is mapped to Mars severity automatically, with an optional per-action override. Setup is a one-time admin task: open the add-on's setup page and enter your Mars webhook URL and token (stored encrypted in Splunk), then enable the action on any saved search. Note: this add-on forwards data to the Mars platform and requires a Mars account.
0 topics and 0 replies mentioned Mars Alert Forwarding Add-on in
Latest Topics
No posts to display.
Latest Replies
No posts to display.
Top Topics
No posts to display.
My Topics
No posts to display.