Deployment Architecture

Splunk SOAR playbook Crowdstrike validation

Sidpet
Loves-to-Learn

I have playbook that validates a url given and assigns scores to it. I am able to run the playbook successfully but do not see the output. where do I see it in the crowdstrike app ? I am new here and trying to learn SOAR.

Labels (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Sidpet 

Have you configured the playbook to output the fields you are interested in seeing? 

Check out https://docs.splunk.com/Documentation/SOAR/current/Playbook/CreatePlaybooks#:~:text=constructing%20y... for more info on how to Add outputs to your playbooks.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

Sidpet
Loves-to-Learn

thank you for the quick response. I have not configured.  since I still learning a little more detail would be a great help. do I add another action block for output or can I configure the end block to do it? can you please share more info to help me 

0 Karma

Sidpet
Loves-to-Learn

I have created a playbook and am trying to run it from an event I have configured. but when I click on the run playbook my playbook does not show in the list what is that I am missing?

0 Karma
Get Updates on the Splunk Community!

Simplifying the Analyst Experience with Finding-based Detections

    Splunk invites you to an engaging Tech Talk focused on streamlining security operations with ...

[Puzzles] Solve, Learn, Repeat: Word Search

This challenge was first posted on Slack #puzzles channelThis puzzle is based on a letter grid containing ...

[Puzzles] Solve, Learn, Repeat: Advent of Code - Day 4

Advent of CodeIn order to participate in these challenges, you will need to register with the Advent of Code ...