Splunk Enterprise Security

Phantom: Multiple Playbook Prompt Options

jamolson
Path Finder

Hello again everyone,
Was wondering if anyone has been able to get Phantom Playbook Prompts to be able to nest response option.
I see that you can select a from a few different types of response options such as "Yes/No", "Message", or "Custom List" but what I would like is actually a "Message" AND a "Custom List" response option in one prompt.
I can do 2 prompts that feed back but I thought it would make more sense to have it all in one.

I am not sure it can even do it but I have been trying to nest the "type"

options = {"type": "list","choices": ["option_1","option_2",]}

to some thing like this

options = {["type": "message"],["type": "list","choices": ["option_1","option_2",]]}

But I cant seem to get phantom to accept it, so I am not sure if it's my syntax or if Phantom just cannot do this.
Has anyone tried?
Thank you

0 Karma

jamolson
Path Finder

Looks like this can be done in the UI on 4.5
We are running a version before this so looks like an upgrade will address this.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...