Splunk SOAR (f.k.a. Phantom)

How to Trigger a Splunk SOAR Playbook on a schedule?

rgrWeidner
Engager

I want to trigger a Splunk SOAR playbook to iterate through a list of hosts every hour and check if they are online in our EDR tool, and if they are online to display a message to the user via the EDR API. Although the playbook is already complete, I can't think of a good way to have it execute every hour. I thought about using a Splunk app ingestion to query our Splunk instance every 60 minutes to create a dummy label and container that the playbook could be set to "active" on, but that seems like an awkward work around. 

 

Is there some other app or setting I'm missing that could achieve this goal?

 

Labels (2)
0 Karma
1 Solution

CS_
Path Finder

I've seen an answer to this before, because I wanted to do the exact same thing. There's no setting or kind of intuitive way to do it.

However in this post it details a way to accomplish it, and it works fairly well.

https://community.splunk.com/t5/Splunk-SOAR-f-k-a-Phantom/How-to-schedule-a-Phantom-playbook-to-run-...



View solution in original post

phanTom
SplunkTrust
SplunkTrust

@rgrWeidner , @CS_ is correct in pointing you to that article! 

Using the timer app you can create containers on  a schedule with a label and title. If you have a playbook set to active for the label you choose then it will run when the timer app creates the container. 

0 Karma

CS_
Path Finder

I've seen an answer to this before, because I wanted to do the exact same thing. There's no setting or kind of intuitive way to do it.

However in this post it details a way to accomplish it, and it works fairly well.

https://community.splunk.com/t5/Splunk-SOAR-f-k-a-Phantom/How-to-schedule-a-Phantom-playbook-to-run-...



Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...