When importing playbooks from the Splunk Research repository https://research.splunk.com/playbooks/ the imported playbooks appear with "Input" status and cannot be activated through the standard interface. Additionally, attempts to delete these inactive playbooks result in errors or incomplete deletion processes.
Question is :
1. Is there a best way to import and activate it? (However, it still needs configuration like an API)
2. Why can't I delete this from the playbook list even though I have logged in with an admin privilege account ?
As the error message describes, you are trying to delete a playbook from a read-only repository. If you are importing it directly from the Splunk security content github repo, then you cannot delete the playbook and would be better off removing the repo in your Source Control settings.
If it is cloned to a repo you control, then you need to uncheck the "read only" setting for that repo.
Still wait the answer
ikaw