Add or manage response actions

Add a response to configure response actions. See Add and manage responses in Splunk Asset and Risk Intelligence.
After you add a response, you can add or manage the actions scheduled to run after the response triggers. The available response actions reflect the alert actions installed on your Splunk platform environment. To see your existing alert actions or create new ones, see Alert actions.

Follow these steps to add or edit response actions.

  1. In Splunk Asset and Risk Intelligence, select Response and then Response management.
  2. Locate the response you want to add actions to.
  3. Select the slider icon in the Actions column.
  4. To add a response action, select Add response action.
    1. Use the drop-down list to select the action you want to add.
    2. Complete any required configuration fields.
    3. Select Add action.
  5. To modify a response action, select the settings icon for the action you want to edit.
  6. To delete a response action, select the X icon for the action you want to remove.
  7. Select Close to return to the response management table.