Splunk Enterprise

Update Splunk notables from Splunk Soar

KiranGd
New Member

Hi Team,

 

is it possible to update/enrich a notable after executing a playbook in splunk soar and that execution output must be attached in the Splunk notable.

Example:

 

Assume I have correlation search named one and this triggers a notable and run a playbook actions. Now once the search triggers and notable is created, the action run a playbook should execute in soar and attach that output to the notable created.

You think of this attaching ip reputation/geo locations of an ip to the notable so that soc can work without logging into virus total or any other sites.

 

Thank you

Labels (1)
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...