Splunk SOAR

Code Block in the playbook?

AliMaher
Path Finder

Hello,

I tried to go through the playbook, and unfortunately found two bad things:

1- If you use the python editor, you can't use the visual editor anymore!!!!!

2- I tried to add a code block to refine an output of the previous step but also I can't continue with the visual editor??

Q: Why this behavior exists? 

Labels (2)
0 Karma

AliMaher
Path Finder

Thanks for your support, in the below example I received a list of IPs and want to check reputation of them using virus total, before that I want to check if those IPs are public or private IP.

I tried to use the Block code, unfortunately I couldn't, so I had to create custom python function and called it in the utility block.

I hope I could use simple code block without enforcing to create custom function.

 

2025-10-11_155756.png

0 Karma

marnall
Motivator

At least in SOAR 6.2+ (IIRC) it should be also possible to make a "Code" block that allows the direct addition of code to a playbook block without having to make and reference a custom function. I recall it having a dark blue block symbol.

0 Karma

marnall
Motivator

This is intended behavior, because the visual editor was not designed to interpret and handle custom code. The visual editor is for applying common configurations, but when you modify the code directly by yourself then you are assuming manual control and cannot rely on the visual editor unless you revert the custom code changes.

Making a code block to refine output of another block should not prevent the previous block from being editable by the visual editor.

Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...