Splunk SOAR (f.k.a. Phantom)

HTTP Post Loops (Modern editor)

New Member


I have a fairly short question.

In the classic editor this worked just fine but in the modern one it simply does not loop the calls.


I have a list of artefacts I want to use in an HTTP Post.

First I am creating my format, something like



{{ "object": "{0}" }}



 I will latest access this format in the Splunk HTTP Apps "post data" action.


When accessing the format as the body using myformat.* I am expecting it to loop for each artefact the format was created for.

What ends up happening is a single request with multiple { "object": "ip1" },  { "object": "ip2" }, etc..


Is there a new way looping is handled in the modern editor?

0 Karma
*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!


Or Learn More in Our Blog >>