Splunk SOAR (f.k.a. Phantom)

How to Trigger a Splunk SOAR Playbook on a schedule?

rgrWeidner
Engager

I want to trigger a Splunk SOAR playbook to iterate through a list of hosts every hour and check if they are online in our EDR tool, and if they are online to display a message to the user via the EDR API. Although the playbook is already complete, I can't think of a good way to have it execute every hour. I thought about using a Splunk app ingestion to query our Splunk instance every 60 minutes to create a dummy label and container that the playbook could be set to "active" on, but that seems like an awkward work around. 

 

Is there some other app or setting I'm missing that could achieve this goal?

 

Labels (2)
0 Karma
1 Solution

CS_
Path Finder

I've seen an answer to this before, because I wanted to do the exact same thing. There's no setting or kind of intuitive way to do it.

However in this post it details a way to accomplish it, and it works fairly well.

https://community.splunk.com/t5/Splunk-SOAR-f-k-a-Phantom/How-to-schedule-a-Phantom-playbook-to-run-...



View solution in original post

phanTom
SplunkTrust
SplunkTrust

@rgrWeidner , @CS_ is correct in pointing you to that article! 

Using the timer app you can create containers on  a schedule with a label and title. If you have a playbook set to active for the label you choose then it will run when the timer app creates the container. 

0 Karma

CS_
Path Finder

I've seen an answer to this before, because I wanted to do the exact same thing. There's no setting or kind of intuitive way to do it.

However in this post it details a way to accomplish it, and it works fairly well.

https://community.splunk.com/t5/Splunk-SOAR-f-k-a-Phantom/How-to-schedule-a-Phantom-playbook-to-run-...



Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...