Splunk SOAR (f.k.a. Phantom)

How can I run on_poll Ingest Action in SOAR app on a schedule?

anniefry
Engager

I am trying to figure out how to get the on-poll action to run outside of a playbook  to be scheduled in the asset settings under the "ingest setting" tab -- in SOAR on the app page, the ingest setting tab isn't showing up even though I've written an on_poll action within my code. I can run the on_poll action from the app page, but I'm not sure how to run it on a schedule.

Labels (1)
0 Karma
1 Solution

ccl0utier
Splunk Employee
Splunk Employee

Hi @anniefry,

I tested this in my own home lab instance and did a bit of research internally.  The App Wizard apparently does not support adding an on poll action at the moment.  I've asked our documentation team to indicate that in our documentation.

Your best bet is to clone an existing app (say the Splunk or Timer ones) and then use the on poll action that is cloned to create your customized one.

Hope that helps.

View solution in original post

anniefry
Engager

Thank you, as this did help. I used the Timer existing app, within the wizard after choosing a custom action to add for a framework of how to add the action. Then I looked at the json for the existing timer app and thoughtfully borrowed the action entry for on_poll. It's working now.

0 Karma

ccl0utier
Splunk Employee
Splunk Employee

Hi @anniefry,

I tested this in my own home lab instance and did a bit of research internally.  The App Wizard apparently does not support adding an on poll action at the moment.  I've asked our documentation team to indicate that in our documentation.

Your best bet is to clone an existing app (say the Splunk or Timer ones) and then use the on poll action that is cloned to create your customized one.

Hope that helps.

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...