Splunk SOAR (f.k.a. Phantom)

Customizable Sound of Phantom

johnteo
Explorer

Hi guys, is there a way to trigger a customizable sound as part of the Phantom Playbook whenever it runs automatically?

Labels (2)
Tags (1)
0 Karma
1 Solution

phantom_mhike
Path Finder

I assume you are asking to have the web UI play a customized sound when a particular playbook runs. The rest of this response is based on that premise.

You can't have the web interface play a custom sound when a playbook executes because the web interface has no awareness of playbooks that are running. There is no reason for it to be aware since it is not responsible for the execution. It only shows you the details that you need to see as context for the view you have open. The only significant callback that the web interface provides out of context is the alerts for prompts and actions since those are directed at individual users and roles.

To accomplish more or less the same goal, you could potentially add a slack notification at the end of your playbook. If you give that slack bot a unique notification sound in your workspace, you will have a customized tone for every time that notification comes in.

I'm not sure what the end goal here is. If you are trying to notify a user that there is a new container for them to look at, then owner assignment will accomplish the same thing with the web interface alerts. If you are trying to alert the masses to an escalated situation, I recommend a more robust response than generating a sound. If it is just for general awareness that the playbook ran successfully, then I generally recommend building monitoring around playbook failures instead. As usage of phantom grows, playbook successes become a constant norm, but errors and failures require attention.

View solution in original post

phantom_mhike
Path Finder

I assume you are asking to have the web UI play a customized sound when a particular playbook runs. The rest of this response is based on that premise.

You can't have the web interface play a custom sound when a playbook executes because the web interface has no awareness of playbooks that are running. There is no reason for it to be aware since it is not responsible for the execution. It only shows you the details that you need to see as context for the view you have open. The only significant callback that the web interface provides out of context is the alerts for prompts and actions since those are directed at individual users and roles.

To accomplish more or less the same goal, you could potentially add a slack notification at the end of your playbook. If you give that slack bot a unique notification sound in your workspace, you will have a customized tone for every time that notification comes in.

I'm not sure what the end goal here is. If you are trying to notify a user that there is a new container for them to look at, then owner assignment will accomplish the same thing with the web interface alerts. If you are trying to alert the masses to an escalated situation, I recommend a more robust response than generating a sound. If it is just for general awareness that the playbook ran successfully, then I generally recommend building monitoring around playbook failures instead. As usage of phantom grows, playbook successes become a constant norm, but errors and failures require attention.

Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...