Splunk Enterprise Security

Palo Alto Adaptive Response from Enterprise Security

Meena_0627
New Member

Hi,

https://answers.splunk.com/answers/589237/splunk-enterprise-security-adaptive-response-actio.html

So this is the same issue I am facing which is mentioned in the above URL.

Now, I am facing the same issue even after defining the fields under "sendalert" in the "alert_actions.conf.spec" file.

Could anyone please help me with this?

Error:

"PAN : Tag to Dynamic Address Group" could not be dispatched: 
ActiveResponseException: Invalid parameter for adhoc modular action.

-Meena

0 Karma

smoir_splunk
Splunk Employee
Splunk Employee

Did you specify the fields in alert_actions.conf or alert_actions.conf.spec? You'll need to specify them in alert_actions.conf.

smoir_splunk
Splunk Employee
Splunk Employee

Without knowing the contents of alert_actions.conf, we'd be unable to help you troubleshoot this further. Please provide more details about what that adaptive response action looks like in the .conf file 🙂

0 Karma
Get Updates on the Splunk Community!

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...