Splunk SOAR (f.k.a. Phantom)

Deleting Custom List Items

CS_
Path Finder

In a playbook, I have a decision tree.

If option A -> Check List -> If Value Exists in custom list -> Do Nothing

Else If Option b -> Check list -> If Value Exists in custom list -> Delete that list entry.

Checking in the SOAR Phantom app actions, I see several options for lists, but no option to "remove/delete listitem" (see attached pic)


How do I go about deleting items from a Custom List?

Thanks!

(SOAR Cloud 5.3.1)

 

 

Labels (2)
0 Karma
1 Solution

phanTom
SplunkTrust
SplunkTrust

@CS_ 

There is an API to perform this in a code block or custom function:

https://docs.splunk.com/Documentation/SOAR/current/PlaybookAPI/DataManagementAPI#delete_from_list 

Otherwise you can rebuild the list without the value(s) and then use set_list to overwrite: 

 https://docs.splunk.com/Documentation/SOAR/current/PlaybookAPI/DataManagementAPI#set_list 

View solution in original post

0 Karma

phanTom
SplunkTrust
SplunkTrust

@CS_ 

There is an API to perform this in a code block or custom function:

https://docs.splunk.com/Documentation/SOAR/current/PlaybookAPI/DataManagementAPI#delete_from_list 

Otherwise you can rebuild the list without the value(s) and then use set_list to overwrite: 

 https://docs.splunk.com/Documentation/SOAR/current/PlaybookAPI/DataManagementAPI#set_list 

0 Karma

CS_
Path Finder

@phanTomAs always, you've dropped the perfect answer. Many thanks!

I'll give this a try (from the first URL you provided)

phantom.delete_from_list(list_name=None, value=None, column=None, remove_all=False, remove_row=False)

 

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...