Splunk SOAR (f.k.a. Phantom)

Playbook stops in between without completing

shaquibk
Explorer

Hi All,

I am quite new to Phantom. I have written few plabooks which works perfectly as intended when run from the debugger. However, the issue is that, when the playbooks are called via automation, the playbooks start executing but stops in between before getting completed. There are error/warnings seen in the container.

How is that the playbook runs fine when called manually from debugger but not when called by automation.

Any leads would be appreciated.

Thanks,

Shaquib

Labels (1)
0 Karma
1 Solution

phanTom
SplunkTrust
SplunkTrust

@shaquibk it would be nice to have visibility of any errors in the container. 

A couple of things can cause what you are seeing:
- Scope
- Badly configured filter

Scope: If you run a playbook against a container once it will see all artifacts, if you run again on the same container without changing the scope, it will only see "New" artifacts so may complain about empty parameters

Filter: IF you just use a filter without a decision in-front and NONE of the conditions are met then it will stop with no indication.

As you say there are errors you see it is unlikely the filter one but until I can see one or more of the errors I am a bit blind. If you can paste the errors here I might be able to better point you to resolution. 

View solution in original post

0 Karma

shaquibk
Explorer

Hey @phanTom 

Thanks for the quick response. My issue is now resolved.

The issue was actually due to badly configured filter. Removing it worked.

Thanks,

Shaquib

0 Karma

phanTom
SplunkTrust
SplunkTrust

@shaquibk it would be nice to have visibility of any errors in the container. 

A couple of things can cause what you are seeing:
- Scope
- Badly configured filter

Scope: If you run a playbook against a container once it will see all artifacts, if you run again on the same container without changing the scope, it will only see "New" artifacts so may complain about empty parameters

Filter: IF you just use a filter without a decision in-front and NONE of the conditions are met then it will stop with no indication.

As you say there are errors you see it is unlikely the filter one but until I can see one or more of the errors I am a bit blind. If you can paste the errors here I might be able to better point you to resolution. 

0 Karma
Get Updates on the Splunk Community!

New Splunk Observability innovations: Deeper visibility and smarter alerting to ...

You asked, we delivered. Splunk Observability Cloud has several new innovations giving you deeper visibility ...

Synthetic Monitoring: Not your Grandma’s Polyester! Tech Talk: DevOps Edition

Register today and join TekStream on Tuesday, February 28 at 11am PT/2pm ET for a demonstration of Splunk ...

Instrumenting Java Websocket Messaging

Instrumenting Java Websocket MessagingThis article is a code-based discussion of passing OpenTelemetry trace ...