Splunk SOAR (f.k.a. Phantom)

How to Trigger a Splunk SOAR Playbook on a schedule?

rgrWeidner
Engager

I want to trigger a Splunk SOAR playbook to iterate through a list of hosts every hour and check if they are online in our EDR tool, and if they are online to display a message to the user via the EDR API. Although the playbook is already complete, I can't think of a good way to have it execute every hour. I thought about using a Splunk app ingestion to query our Splunk instance every 60 minutes to create a dummy label and container that the playbook could be set to "active" on, but that seems like an awkward work around. 

 

Is there some other app or setting I'm missing that could achieve this goal?

 

Labels (2)
0 Karma
1 Solution

CS_
Path Finder

I've seen an answer to this before, because I wanted to do the exact same thing. There's no setting or kind of intuitive way to do it.

However in this post it details a way to accomplish it, and it works fairly well.

https://community.splunk.com/t5/Splunk-SOAR-f-k-a-Phantom/How-to-schedule-a-Phantom-playbook-to-run-...



View solution in original post

phanTom
SplunkTrust
SplunkTrust

@rgrWeidner , @CS_ is correct in pointing you to that article! 

Using the timer app you can create containers on  a schedule with a label and title. If you have a playbook set to active for the label you choose then it will run when the timer app creates the container. 

0 Karma

CS_
Path Finder

I've seen an answer to this before, because I wanted to do the exact same thing. There's no setting or kind of intuitive way to do it.

However in this post it details a way to accomplish it, and it works fairly well.

https://community.splunk.com/t5/Splunk-SOAR-f-k-a-Phantom/How-to-schedule-a-Phantom-playbook-to-run-...



Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...