Splunk SOAR (f.k.a. Phantom)

How can I run on_poll Ingest Action in SOAR app on a schedule?

anniefry
Engager

I am trying to figure out how to get the on-poll action to run outside of a playbook  to be scheduled in the asset settings under the "ingest setting" tab -- in SOAR on the app page, the ingest setting tab isn't showing up even though I've written an on_poll action within my code. I can run the on_poll action from the app page, but I'm not sure how to run it on a schedule.

Labels (1)
0 Karma
1 Solution

ccl0utier
Splunk Employee
Splunk Employee

Hi @anniefry,

I tested this in my own home lab instance and did a bit of research internally.  The App Wizard apparently does not support adding an on poll action at the moment.  I've asked our documentation team to indicate that in our documentation.

Your best bet is to clone an existing app (say the Splunk or Timer ones) and then use the on poll action that is cloned to create your customized one.

Hope that helps.

View solution in original post

anniefry
Engager

Thank you, as this did help. I used the Timer existing app, within the wizard after choosing a custom action to add for a framework of how to add the action. Then I looked at the json for the existing timer app and thoughtfully borrowed the action entry for on_poll. It's working now.

0 Karma

ccl0utier
Splunk Employee
Splunk Employee

Hi @anniefry,

I tested this in my own home lab instance and did a bit of research internally.  The App Wizard apparently does not support adding an on poll action at the moment.  I've asked our documentation team to indicate that in our documentation.

Your best bet is to clone an existing app (say the Splunk or Timer ones) and then use the on poll action that is cloned to create your customized one.

Hope that helps.

Get Updates on the Splunk Community!

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...

Splunkbase | Splunk Dashboard Examples App for SimpleXML End of Life

The Splunk Dashboard Examples App for SimpleXML will reach end of support on Dec 19, 2024, after which no new ...

Understanding Generative AI Techniques and Their Application in Cybersecurity

Watch On-Demand Artificial intelligence is the talk of the town nowadays, with industries of all kinds ...