Splunk SOAR (f.k.a. Phantom)

SOAR: Is it possible to retrieve the (splunk soar) instance details inside a playbook?

goncalocoelho
Path Finder

Hi All,

is it possible to retrieve the (splunk soar) instance details inside a playbook?

For instance when sending an email, I want to be able to tell if the playbook ran in dev or prod environment.

Is there a list of all the global environment variables?

 

Thanks in advance

Labels (2)
Tags (2)
0 Karma
1 Solution

phanTom
SplunkTrust
SplunkTrust

@goncalocoelho the best way, IMO, will be to use REST and hit the `/rest/system_settings` endpoint and get something from the company_info_settings to determine if dev/prod. 

E.g. If you set the system/instance name to reflect the environment you could parse that, or just use the fqdn setting to work out where it came from. 

This will need to be coded either in a code block or custom function. 

View solution in original post

0 Karma

phanTom
SplunkTrust
SplunkTrust

@goncalocoelho the best way, IMO, will be to use REST and hit the `/rest/system_settings` endpoint and get something from the company_info_settings to determine if dev/prod. 

E.g. If you set the system/instance name to reflect the environment you could parse that, or just use the fqdn setting to work out where it came from. 

This will need to be coded either in a code block or custom function. 

0 Karma

goncalocoelho
Path Finder

Thanks for your reply @phanTom, that seems a very good approach!

I'll try that and share my findings here for everyone

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...