Security

sending a tcp packet as splunk soar action

yossisplunk
New Member

In a part of splunk soar (phantom) playbook I would like, in some cases, to send a syslog msg to a remote syslog server.
I did not find any well-known app which can help me, so I figure out creating it as a (python) code  via "Python Playbook Editor".

BUT somehow using the default socket library and the connect + send functions did not work.
Listening to all network interfaces did not show any attempt creating the tcp flow to the destination.

Could someone help me or show me how can I can open a tcp connection in splunk SOAR 🙏

 

Screenshot 2023-12-20 155112.png

Labels (1)
Tags (2)
0 Karma

diogofgm
SplunkTrust
SplunkTrust

I dont think there is a connector for that purpose. If you want to follow the "develop your own solution" route i would recommend building a connector for SOAR instead of a function in the visual editor. IMO its more flexible on what you can do (e.g. include external libs) and its easily reusable and you can add multiple assets to use in the PBs. Also, the new app wizard makes it easier to get started and you have tons of "examples" if you look in the SOAR connector GitHub account

------------
Hope I was able to help you. If so, some karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...