<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to update an artifact field? in Splunk SOAR</title>
    <link>https://community.splunk.com/t5/Splunk-SOAR/How-to-update-an-artifact-field/m-p/619917#M1010</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222170"&gt;@phanTom&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good to know. When I was trying to do that before, that was back in 4.6.X something. It's been awhile.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/249062"&gt;@scorsatto&lt;/a&gt;&amp;nbsp;Listen to him! He's got the evidence.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 07 Nov 2022 15:41:31 GMT</pubDate>
    <dc:creator>Dave_Burns</dc:creator>
    <dc:date>2022-11-07T15:41:31Z</dc:date>
    <item>
      <title>How to update an artifact field?</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/How-to-update-an-artifact-field/m-p/619197#M1001</link>
      <description>&lt;P&gt;is there an option to update the value of a specific field within a specific artifact? I was able to update using phantom update_artifact action or with a REST call, but when the field is updated it also delete the other existent fields in that artifact.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 02:39:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/How-to-update-an-artifact-field/m-p/619197#M1001</guid>
      <dc:creator>scorsatto</dc:creator>
      <dc:date>2022-11-02T02:39:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to update an artifact field?</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/How-to-update-an-artifact-field/m-p/619904#M1008</link>
      <description>&lt;P&gt;The interfaces only seem to update the entire artifact.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could create a custom function where you provide the artifact id, field to change, and new value.&amp;nbsp;&lt;/P&gt;&lt;P&gt;It fetches the entire artifact first, change the field value, and then "re-save" that artifact.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;That way you have something modular if you need to do it again in the future.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 15:23:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/How-to-update-an-artifact-field/m-p/619904#M1008</guid>
      <dc:creator>Dave_Burns</dc:creator>
      <dc:date>2022-11-07T15:23:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to update an artifact field?</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/How-to-update-an-artifact-field/m-p/619915#M1009</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/249062"&gt;@scorsatto&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244875"&gt;@Dave_Burns&lt;/a&gt;&amp;nbsp;I am not sure what version you may be on but the update_artifact action on the Phantom Phantom app does update and doesn't overwrite, unless you tick the box.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I simply put the JSON of the field I wanted to update in the 'cef_json' field and it updated and didn't overwrite.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="phanTom_2-1667835459241.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22374i249CDC3CAECCCD06/image-size/medium?v=v2&amp;amp;px=400" role="button" title="phanTom_2-1667835459241.png" alt="phanTom_2-1667835459241.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="phanTom_0-1667835437156.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22372iEDDD4725C60BC32D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="phanTom_0-1667835437156.png" alt="phanTom_0-1667835437156.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="phanTom_1-1667835447182.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22373iDC5D4D75666DE934/image-size/medium?v=v2&amp;amp;px=400" role="button" title="phanTom_1-1667835447182.png" alt="phanTom_1-1667835447182.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Bear in mind if you are trying to add the same CEF field to an existing artifact, it won't work as you would need a new artifact. If you use update artifact to ADD the same field with a different value, then it will overwrite due to the above.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 15:40:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/How-to-update-an-artifact-field/m-p/619915#M1009</guid>
      <dc:creator>phanTom</dc:creator>
      <dc:date>2022-11-07T15:40:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to update an artifact field?</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/How-to-update-an-artifact-field/m-p/619917#M1010</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222170"&gt;@phanTom&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good to know. When I was trying to do that before, that was back in 4.6.X something. It's been awhile.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/249062"&gt;@scorsatto&lt;/a&gt;&amp;nbsp;Listen to him! He's got the evidence.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 15:41:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/How-to-update-an-artifact-field/m-p/619917#M1010</guid>
      <dc:creator>Dave_Burns</dc:creator>
      <dc:date>2022-11-07T15:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to update an artifact field?</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/How-to-update-an-artifact-field/m-p/619927#M1011</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244875"&gt;@Dave_Burns&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222170"&gt;@phanTom&lt;/a&gt;. that exact what I did, I've created a new CF that get all the data from the artifact first, after that changes the fields I want and then I can use this CF payload result in the update artifact action. it seems the interface always replace the whole artifact data with whatever you post, this is not very clear on the documentation of the app&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 16:10:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/How-to-update-an-artifact-field/m-p/619927#M1011</guid>
      <dc:creator>scorsatto</dc:creator>
      <dc:date>2022-11-07T16:10:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to update an artifact field?</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/How-to-update-an-artifact-field/m-p/632218#M1140</link>
      <description>&lt;P&gt;Hi, saw the answers and they are very close to what I also need but I would additionally want to place new key:value pair under the already existing key.&lt;BR /&gt;&lt;BR /&gt;E.g. Add new key "test" under existing "test_header"&lt;/P&gt;&lt;P&gt;"cef": {&lt;BR /&gt;"test_header": {&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; "test": "value"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 15:16:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/How-to-update-an-artifact-field/m-p/632218#M1140</guid>
      <dc:creator>licroBI_0x1</dc:creator>
      <dc:date>2023-02-24T15:16:57Z</dc:date>
    </item>
  </channel>
</rss>

