Splunk® Enterprise Security

Troubleshoot Splunk Enterprise Security

Troubleshoot for adaptive response actions not displaying

Issue

An adaptive response action is not available for selection on the detection editor or the View details page for the finding or investigation in Mission Control.

Cause

Your role might not have permissions to view and use the adaptive response action.

Solution

  • Check the alert actions manager to determine if the adaptive response actions exist in Splunk platform.
  • If the adaptive response actions from an add-on do not appear in Splunk Enterprise Security, but appear in the alert actions manager, make sure that the add-on is exported globally.
  • If you can select the adaptive response action on the detection editor, but not on the Mission Control page, the adaptive response action might be an ordinary alert action, or the response action does not support ad hoc invocation.
Last modified on 07 August, 2024
Troubleshoot new users not displaying in the analyst queue   Troubleshoot adaptive response relays from Splunk Cloud Platform Enterprise Security search head to an on-premises device

This documentation applies to the following versions of Splunk® Enterprise Security: 8.0.0


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters