Splunk SOAR

Code Block in the playbook?

AliMaher
Path Finder

Hello,

I tried to go through the playbook, and unfortunately found two bad things:

1- If you use the python editor, you can't use the visual editor anymore!!!!!

2- I tried to add a code block to refine an output of the previous step but also I can't continue with the visual editor??

Q: Why this behavior exists? 

Labels (2)
0 Karma

AliMaher
Path Finder

Thanks for your support, in the below example I received a list of IPs and want to check reputation of them using virus total, before that I want to check if those IPs are public or private IP.

I tried to use the Block code, unfortunately I couldn't, so I had to create custom python function and called it in the utility block.

I hope I could use simple code block without enforcing to create custom function.

 

2025-10-11_155756.png

0 Karma

marnall
Motivator

At least in SOAR 6.2+ (IIRC) it should be also possible to make a "Code" block that allows the direct addition of code to a playbook block without having to make and reference a custom function. I recall it having a dark blue block symbol.

0 Karma

marnall
Motivator

This is intended behavior, because the visual editor was not designed to interpret and handle custom code. The visual editor is for applying common configurations, but when you modify the code directly by yourself then you are assuming manual control and cannot rely on the visual editor unless you revert the custom code changes.

Making a code block to refine output of another block should not prevent the previous block from being editable by the visual editor.

Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...