Splunk SOAR

demote a case during using playbook

meshorer
Path Finder

hi all,

is there a way to demote a case to a container using a playbook?

 

thank you in advance

Labels (1)
0 Karma
1 Solution

phanTom
SplunkTrust
SplunkTrust

@meshorer you just need to update the "container_type" key on the container to "default". 

REST is usually the best mechanism for this but the `phantom.update()` call might also work. 

API:
https://docs.splunk.com/Documentation/SOARonprem/6.1.1/PlaybookAPI/ContainerAPI#update 

REST: 
https://docs.splunk.com/Documentation/SOARonprem/6.1.1/PlatformAPI/RESTContainers 

View solution in original post

0 Karma

phanTom
SplunkTrust
SplunkTrust

@meshorer you just need to update the "container_type" key on the container to "default". 

REST is usually the best mechanism for this but the `phantom.update()` call might also work. 

API:
https://docs.splunk.com/Documentation/SOARonprem/6.1.1/PlaybookAPI/ContainerAPI#update 

REST: 
https://docs.splunk.com/Documentation/SOARonprem/6.1.1/PlatformAPI/RESTContainers 

0 Karma
Get Updates on the Splunk Community!

Let’s Talk Terraform

If you’re beyond the first-weeks-of-a-startup stage, chances are your application’s architecture is pretty ...

Cloud Platform | Customer Change Announcement: Email Notification is Available For ...

The Notification Team is migrating our email service provider. As the rollout progresses, Splunk has enabled ...

Save the Date: GovSummit Returns Wednesday, December 11th!

Hey there, Splunk Community! Exciting news: Splunk’s GovSummit 2024 is returning to Washington, D.C. on ...