Splunk Enterprise Security

How do you access notable event IDs from adaptive response Python code?

ramesh_babu71
Path Finder

Hi,

I have a few adaptive responses (AR) which are tagged to run on correlation rule triggering. These Adaptive responses are working fine and getting the data. Now I want to save this AR data to a KVstore and tagged with an associated notable event ID. My intention is to fetch this data later using the notable event ID field.

However, I can't find any way to access/get the notable event ID from within the adaptive response code. I tried using the helper.get_events() but it doesn't have a notable event ID field. Please let me know if anyone has done this before.

Regards,
Ramesh

0 Karma

chli_splunk
Splunk Employee
Splunk Employee

What notable event id you want to use? Could you please post your codes?

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...