Skip to content

dc401/Splunk_Remediation_Scripts

Repository files navigation

Splunk Remediation Alert Defense Scripts

Make use of your SIEM's capabilities to be a SOAR without buying a one. This repo houses sample scripts to perform auto-defending and remediation of adverse conditions on your network using Splunk Enterprise.

This is part of a tutorial written on Medium, please follow the link below for more context. Auto Defending and Healing Networks by Extending SIEM Value

Action alert script wrapper

Example use case for post action alert scripts