Splunk® Enterprise Security

Use Splunk Enterprise Security

Download manual as PDF

Download topic as PDF

Included adaptive response actions with Splunk Enterprise Security

Splunk Enterprise Security includes several adaptive response actions that you can run on a notable event from Incident Review.

Note: ES admins can configure these and additional adaptive response actions to be triggered by correlation searches. See Configure adaptive response actions for a correlation search in Splunk Enterprise Security in Administer Splunk Enterprise Security.

Modify a risk score with a risk modifier

Modify a risk score as a result of a correlation search or in response to notable event details with the Risk Analysis adaptive response action. The risk adaptive response action creates a risk modifier event. You can view the risk modifier events on the Risk Analysis dashboard in Enterprise Security.

  1. Click Add New Response Action and select Risk Analysis.
  2. Type the score to assign to the risk object.
  3. Select a field from the notable event to apply the risk score to for the Risk Object Field.
  4. Select the Risk Object Type to apply the risk score to.

Run a script

Run a script stored in $SPLUNK_HOME/bin/scripts.

  1. Click Add New Response Action and select Run a script.
  2. Type the filename of the script.

More information about scripted alerts can be found in the Splunk platform documentation.

Start a stream capture with Splunk Stream

Start a Stream capture to capture packets on the IP addresses of the selected protocols over the time period that you select. You can view the results of the capture session on the Protocol Intelligence dashboards.

A stream capture will not work unless you integrate Splunk Stream with Splunk Enterprise Security. See Splunk Stream integration.

  1. Click Add New Response Action and select Stream Capture to start a packet capture in response to a correlation search match.
  2. Type a Description to describe the stream created in response to the correlation search match.
  3. Type a Category to define the type of stream capture. You can view streams by category in Splunk Stream.
  4. Type the comma-separated event fields to search for IP addresses for the Stream capture. The first non-null field is used for the capture.
  5. Type the comma-separated list of protocols to capture.
  6. Select a Capture duration to define the length of the packet capture.
  7. Type a Stream capture limit to limit the number of stream captures started by the correlation search.

Ping a host

Determine whether a host is still active on the network by pinging the host.

  1. Click Add New Response Action and select Ping.
  2. Select the field that contains the host that you want to ping in the Host Field.
  3. Type the number of maximum results that the ping returns. Defaults to 1.

Run nbtstat

Learn more about a host and the services that the host runs by running nbtstat. You must have nbtstat installed on the search head for this to run successfully.

  1. Click Add New Response Action and select Nbtstat.
  2. Select the field that contains the host that you want to run the nbtstat for in the Host Field.
  3. Type the number of maximum results that the nbtstat returns. Defaults to 1.

Run nslookup

Look up the domain name of an IP address, or the IP address of a domain name, by running nslookup. You must have nslookup installed on the search head for this to run.

  1. Click Add New Response Action and select Nslookup.
  2. Select the field that contains the host that you want to run the nslookup for in the Host Field.
  3. Type the number of maximum results that the nslookup returns. Defaults to 1.

Add threat intelligence

Create threat artifacts in a threat collection.

  1. Click Add New Response Action and select Add Threat Intelligence.
  2. Select the Threat Group to attribute this artifact to.
  3. Select the Threat Collection to add the threat artifact to.
  4. Select the Field from event that contains the value to add as a threat artifact to the threat intelligence collection.
  5. Type a Description for the threat artifact.
  6. Type a Weight associated with the threat list. Defaults to 1.
  7. Type a number of Max Results to specify the number of results to process as threat artifacts. Each unique search field value counts as a result. Defaults to 100.
PREVIOUS
Take action on a notable event on Incident Review in Splunk Enterprise Security
  NEXT
How urgency is assigned to notable events in Splunk Enterprise Security

This documentation applies to the following versions of Splunk® Enterprise Security: 5.0.0, 5.0.1, 5.1.0, 5.1.1, 5.2.0, 5.2.1, 5.2.2, 5.3.0


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters