Splunk Enterprise Security

How do I get the alert actions from splunk_ta_snow to be active as adaptive responses in Enterprise Security

las
Contributor

Hi.

It seems like the alert_actions defines in splunk_ta_snow misses param._cam parms, so they don't show up, as adaptive responses in Enterprise Security.

How do I get them to do that?

Kind regards
Lars Søndergaard

0 Karma

rpille_splunk
Splunk Employee
Splunk Employee

The ServiceNow alert actions should already be available to be triggered as adaptive response actions from correlation searches, provided that the permissions are set correctly so that the ServiceNow alert actions are available to all apps. However, in order to get them to appear as an option as an ad-hoc adaptive response from the Incident Review dashboard, you'll need the param._cam, which you can add on your own instance:

Follow the docs to do this here: http://dev.splunk.com/view/enterprise-security/SP-CAAAFBG

0 Karma

nickhills
Ultra Champion

The current version of Splunk_TA_snow 3.1 does not include adaptive response actions.
It might be something introduced in a later version (a new release is due any time now to support the latest SNOW platform), however I suspect Phantom would be a more "supportable" approach for the future

If my comment helps, please give it a thumbs up!
0 Karma

las
Contributor

Then I'll have to purchase Phantom, and provision hardware for that also, or have I missunderstood the licenzing and deployment options.

I must admit, I haven't really lokked into phantom yet.

Kind regards
Lars

0 Karma

nickhills
Ultra Champion

Maybe - maybe not.
You can still use the alert framework to raise service now tickets/incidents (using Splunk_TA_snow), just not as adaptive response actions.

With regard to Phantom - yes it is a separate product and licence. I have no experience with it, so cant really comment on how it works.

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...
OSZAR »