Splunk SOAR

Change parameter dynamically In playbook

meshorer
Path Finder

Hi,

during a playbook, 

I would like to check a parameter with a condition, and if the condition result true, I would like to use that parameter. But if the condition result is false, I would then use a different parameter.

is there a way to do that without duplicating a lot of blocks? 

Labels (1)
0 Karma
1 Solution

phanTom
SplunkTrust
SplunkTrust

@meshorer when you join 2 or more lines to a block it creates a join that by default will wait for all connected blocks to complete. 

If you open the code block settings and expand the Advanced drop-down you should see some tick boxes. As long as the 2 block prior could only ever go down 1 route then you can untick all boxes and it should work. 

View solution in original post

0 Karma

phanTom
SplunkTrust
SplunkTrust

@meshorer is the value you would use when NOT true hardcoded or from other information in the event/artifact?

I think for this you might be best to use a Code Block / Custom Function to have a single output and do all the checking in code based on the inputted value(s). 

-- Happy SOARing! --

0 Karma

meshorer
Path Finder

Thank you, @phanTom 

a code block to check it and then outputs the relevant parameter did it.

but now I have another problem- when I  try to connect two blocks that are separated with a decision block, to the same prompt block or decision block, it doesn’t work.

for one case it goes well, but for the second case the debug shows “join_ <block name> called”, but the playbook ends there.

Why does it happen?

0 Karma

phanTom
SplunkTrust
SplunkTrust

@meshorer when you join 2 or more lines to a block it creates a join that by default will wait for all connected blocks to complete. 

If you open the code block settings and expand the Advanced drop-down you should see some tick boxes. As long as the 2 block prior could only ever go down 1 route then you can untick all boxes and it should work. 

0 Karma

meshorer
Path Finder

@phanTom 

you are a genius! 

thank you very much

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...