Splunk SOAR (f.k.a. Phantom)

How can I run on_poll Ingest Action in SOAR app on a schedule?

anniefry
Engager

I am trying to figure out how to get the on-poll action to run outside of a playbook  to be scheduled in the asset settings under the "ingest setting" tab -- in SOAR on the app page, the ingest setting tab isn't showing up even though I've written an on_poll action within my code. I can run the on_poll action from the app page, but I'm not sure how to run it on a schedule.

Labels (1)
0 Karma
1 Solution

ccl0utier
Splunk Employee
Splunk Employee

Hi @anniefry,

I tested this in my own home lab instance and did a bit of research internally.  The App Wizard apparently does not support adding an on poll action at the moment.  I've asked our documentation team to indicate that in our documentation.

Your best bet is to clone an existing app (say the Splunk or Timer ones) and then use the on poll action that is cloned to create your customized one.

Hope that helps.

View solution in original post

anniefry
Engager

Thank you, as this did help. I used the Timer existing app, within the wizard after choosing a custom action to add for a framework of how to add the action. Then I looked at the json for the existing timer app and thoughtfully borrowed the action entry for on_poll. It's working now.

0 Karma

ccl0utier
Splunk Employee
Splunk Employee

Hi @anniefry,

I tested this in my own home lab instance and did a bit of research internally.  The App Wizard apparently does not support adding an on poll action at the moment.  I've asked our documentation team to indicate that in our documentation.

Your best bet is to clone an existing app (say the Splunk or Timer ones) and then use the on poll action that is cloned to create your customized one.

Hope that helps.

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...