Splunk SOAR

Cannot delete the imported playbook

zksvc
Contributor

When importing playbooks from the Splunk Research repository https://research.splunk.com/playbooks/  the imported playbooks appear with "Input" status and cannot be activated through the standard interface. Additionally, attempts to delete these inactive playbooks result in errors or incomplete deletion processes.

Question is : 
1. Is there a best way to import and activate it? (However, it still needs configuration like an API)
2. Why can't I delete this from the playbook list even though I have logged in with an admin privilege account ?

zksvc_0-1748337847116.jpeg

zksvc_1-1748337853715.jpeg

 

 

 

0 Karma

marnall
Motivator

As the error message describes, you are trying to delete a playbook from a read-only repository. If you are importing it directly from the Splunk security content github repo, then you cannot delete the playbook and would be better off removing the repo in your Source Control settings.

If it is cloned to a repo you control, then you need to uncheck the "read only" setting for that repo.

0 Karma

zksvc
Contributor

Still wait the answer

0 Karma

zksvc
Contributor

ikaw

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...