Once a threat is confirmed, speed is critical. Adaptive Response Actions in Splunk ES allow analysts to trigger automated containment steps directly from Incident Review.
Examples include: pinging a host to verify it's alive, running a script to isolate the endpoint from the network, or sending the malicious hash to an EDR for a global block.