- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Update Splunk notables from Splunk Soar
KiranGd
New Member
05-17-2024
08:51 AM
Hi Team,
is it possible to update/enrich a notable after executing a playbook in splunk soar and that execution output must be attached in the Splunk notable.
Example:
Assume I have correlation search named one and this triggers a notable and run a playbook actions. Now once the search triggers and notable is created, the action run a playbook should execute in soar and attach that output to the notable created.
You think of this attaching ip reputation/geo locations of an ip to the notable so that soc can work without logging into virus total or any other sites.
Thank you
