<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Email user and get response back in Splunk SOAR</title>
    <link>https://community.splunk.com/t5/Splunk-SOAR/Email-user-and-get-response-back/m-p/676866#M1423</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222170"&gt;@phanTom&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;SPAN&gt;Hope my message finds you well.&lt;BR /&gt;&lt;/SPAN&gt;Are those playbooks by chance in the community repository?&lt;/P&gt;</description>
    <pubDate>Wed, 07 Feb 2024 17:44:25 GMT</pubDate>
    <dc:creator>MrM1</dc:creator>
    <dc:date>2024-02-07T17:44:25Z</dc:date>
    <item>
      <title>Email user and get response back</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Email-user-and-get-response-back/m-p/558057#M664</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am looking send an email to user with simple yes/no response which I can then use to handle the case. I know Palo Alto’s soar has some integrations to handle this. Do we have similar func in Splunk or any idea on how to implement them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 18:01:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Email-user-and-get-response-back/m-p/558057#M664</guid>
      <dc:creator>rodneyjerome</dc:creator>
      <dc:date>2021-07-01T18:01:38Z</dc:date>
    </item>
    <item>
      <title>Re: Email user and get response back</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Email-user-and-get-response-back/m-p/558123#M665</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/197211"&gt;@rodneyjerome&lt;/a&gt;&amp;nbsp;it's not out of the box but the way I have done this is with 2 playbooks:&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; 1st/any playbook that sends an email that expects a response first builds an encrypted string that contains useful information for the response (&amp;nbsp; i use container_id + label value ), then builds a HTML body with the token inserted with an obvious prefix ( easy to pick out in regex )&amp;nbsp; and then sends the email and completes.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the middle, you have an app monitoring and ingesting from the mailbox/folder where the user will be replying to.&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. 2nd playbook runs on these ingested emails, retrieves the key value, decrypts it and then uses the information to understand which container to update/work on.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;This can be expanded nicely by adding more relevant information into the inserted key.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2021 08:14:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Email-user-and-get-response-back/m-p/558123#M665</guid>
      <dc:creator>phanTom</dc:creator>
      <dc:date>2021-07-02T08:14:53Z</dc:date>
    </item>
    <item>
      <title>Re: Email user and get response back</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Email-user-and-get-response-back/m-p/676866#M1423</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222170"&gt;@phanTom&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;SPAN&gt;Hope my message finds you well.&lt;BR /&gt;&lt;/SPAN&gt;Are those playbooks by chance in the community repository?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2024 17:44:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Email-user-and-get-response-back/m-p/676866#M1423</guid>
      <dc:creator>MrM1</dc:creator>
      <dc:date>2024-02-07T17:44:25Z</dc:date>
    </item>
  </channel>
</rss>

