Splunk SOAR (f.k.a. Phantom)

Playbook run on bulk events

ThomasC
New Member

Hi all,

I have a large number of events that have been ingested into SOAR from a Service Now queue.

A large amount of these events have been closed on the Service Now end, however, the events are still open in SOAR.

I have written a playbook to check the status of these tickets in Service Now then close the event in SOAR if certain conditions are met.

I am having trouble finding out how I can run this playbook on all of the events in the source as I can only select 50 at a time.

If someone could point me in the right direction to run this playbook on all of the events in the source that would be very helpful.

Thank you for reading.

Labels (1)
0 Karma

phanTom
SplunkTrust
SplunkTrust

@ThomasC you are going to need a combination of REST and the playbook API. 

  1. Use REST to get all container_ids for a label
    1. /rest/container?_filter_label="<label>"&page_size=0
    2. https://docs.splunk.com/Documentation/SOARonprem/6.1.1/PlaybookAPI/SessionAPI 
  2. Then create a loop where you use the phantom.playbook() API to call the playbook against each container id. 
    1. https://docs.splunk.com/Documentation/SOARonprem/6.1.1/PlaybookAPI/PlaybookAPI#playbook 

The above can be done in a single custom function / Code Block. 

Also if you need these to run without you having to do historical backfill like this, you just need to set your playbook to Active and it will run automatically when an even with the relevant label drops into the queue from SNOW. 

-- Happy SOARing! --

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...