All Apps and Add-ons

'str' object has no attribute 'get'  -

g_cremin
Loves-to-Learn

Hello Everyone, I'm trying to create an app in Splunk-SOAR version 6.4.0.92, using miminal code but keeps getting this error 'str' object has no attribute 'get'  -  when I try to install it on the apps section of Splunk-SOAR dashboard.  Can anyone help with this please

Error MessageError Messageapp.jsonapp.json

Screenshot 2025-04-16 163949.png

 

Labels (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @g_cremin 

I believe "actions" should be an array of actions, not a dict? This might be affecting things.

...
 "actions": [
    {
        "action":"test_connectivity",
        "identifier": "test_connectivity",
        "description": "Tests connectivity to Wazuh",
        "type": "test",
        "read_only": true,
        "parameters": [],
        "output": []
    }
],
...

For more detail on the app.json schema check out https://docs.splunk.com/Documentation/SOAR/current/DevelopApps/Metadata

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

g_cremin
Loves-to-Learn

Thanking you for replying - I've tried both but throws out a different error.  I was told that splunk-soar version 6.4.0.92 only takes dict { }.  I've attached the error message for the array error...Error message for array [ ]Error message for array [ ]

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...