Set up adaptive response actions in Splunk App for PCI Compliance

Adaptive response actions allow you to gather information or take other action in response to the results of a correlation search or the details of a notable event. Splunk App for PCI Compliance includes several adaptive response actions. See Included adaptive response actions with Splunk App for PCI Compliance.

You can add adaptive response actions and alert actions to correlation searches, or run adaptive response actions from notable events on the Incident Review dashboard. Collect information before you start your investigation to save time at triage by adding adaptive response actions to correlation searches. Take action at triage time by running adaptive response actions from the Incident Review dashboard.

Add new adaptive response actions

To add new adaptive response actions, you can install add-ons with adaptive response actions or create your own adaptive response actions. See Create an adaptive response action on the Splunk developer portal for information on creating adaptive response actions. See Install and deploy add-ons in the Install and Upgrade Manual.

Configure permissions for adaptive response actions

Restrict certain adaptive response actions to certain roles by adjusting the permissions for adaptive response actions in the alert actions manager. You can find information about the alert actions manager in the Splunk platform documentation.

In order to run adaptive response actions from the Incident Review dashboard that have credentials stored in the credential manager, you must have the appropriate capability.

  • For Splunk platform version 6.5.0 and later, list_storage_passwords.
  • For earlier Splunk platform versions, admin_all_objects.

Add an adaptive response action to a correlation search

Troubleshoot why an adaptive response action is not available to select

If an adaptive response action is not available to select on the correlation search editor or Incident Review, several things could be the cause.

  • Your role may not have permissions to view and use the adaptive response action. See Using the alert actions manager in the Alerting Manual.
  • Check the alert actions manager to determine if the adaptive response actions exist in Splunk platform. See Using the alert actions manager in the Alerting Manual.
  • If the adaptive response actions from an add-on do not appear in Splunk App for PCI Compliance, but do appear in the alert actions manager, make sure that the add-on is being imported by Splunk App for PCI Compliance. See Install and deploy add-ons in the Install and Upgrade Manual.
  • If you can select the adaptive response action on the correlation search editor, but not on Incident Review, the adaptive response action might be an ordinary alert action, or the response action does not support ad-hoc invocation. See Determine whether your action supports ad hoc invocation on the Splunk developer portal.