Splunk SOAR (f.k.a. Phantom)

is it possible for branch to go back to original flow in playbook

Qingguo
Engager

Hi team

I found main flow will not run after adding branch flow ,  is it known limitation ?

Screen Shot 2021-11-16 at 8.55.19 PM.png

 

thanks

Labels (1)
Tags (1)
0 Karma
1 Solution

phanTom
SplunkTrust
SplunkTrust

@Qingguo have you checked the join on the block with 2 entry points?

If you select the "Add tag to container" block (in edit mode) and in the left-hand side select Settings > Advanced you may see one or more boxes with ticks in. This means that the block is waiting for something to run/complete and it's likely that if it goes on the `condition1` path its expecting the "set tag for instance retry" to have run but if that path isn't taken then it will never run. 

Anytime you add more than 1 line to a block, phantom will automatically add the joins for all connected actions upstream. 

Hope this helps? Mark as solution if so 😛 

 

View solution in original post

0 Karma

phanTom
SplunkTrust
SplunkTrust

@Qingguo have you checked the join on the block with 2 entry points?

If you select the "Add tag to container" block (in edit mode) and in the left-hand side select Settings > Advanced you may see one or more boxes with ticks in. This means that the block is waiting for something to run/complete and it's likely that if it goes on the `condition1` path its expecting the "set tag for instance retry" to have run but if that path isn't taken then it will never run. 

Anytime you add more than 1 line to a block, phantom will automatically add the joins for all connected actions upstream. 

Hope this helps? Mark as solution if so 😛 

 

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Customer Survey!

If you use Splunk Observability Cloud, we invite you to share your valuable insights with us through a brief ...

Happy CX Day, Splunk Community!

Happy CX Day, Splunk Community! CX stands for Customer Experience, and today, October 3rd, is CX Day — a ...

.conf23 | Get Your Cybersecurity Defense Analyst Certification in Vegas

We’re excited to announce a new Splunk certification exam being released at .conf23! If you’re going to Las ...