Splunk SOAR

Disable Active Playbook from Automatically Running When Artifact Added

stauff
Explorer

Hello All!  I'm trying to figure out how to stop an active playbook from auto running when an artifact is added to a case via the GUI.  I can't seem to find any documentation or option to turn this functionality off.  Is there a setting for this?  Or do I need to add logic to my playbook so it cancels itself if it has already been run on the current container?

Labels (2)
Tags (1)
0 Karma
1 Solution

phanTom
SplunkTrust
SplunkTrust

@stauff there are a few ways to stop this, my main preference is only adding artifacts via methods where you can stipulate run_automation = False. The 3 ways this is possible at the moment are:

  • REST Call to add artifact and set run_automation to False Artifact REST Docs 
  • Use the Phantom Phantom app's add_artifact call and untick the run_automation option
  • Use the extract_ioc action in the Parser app and untick the run_automation 

The issue is that if you add manually to a container then it will NOT provide this option so in this case it would be best to add a tag to the event to state it's been "processed" already and then have a decision at the beginning that looks for that tag and ends if it exists. This can get messy in the activity pane if you are adding a lot manually but will work. 

Personally I would recommend controlling the addition of artifacts by a playbook, maybe with a prompt for artifact info and then use REST or the add_artifact to add the data with the run_automation set to False. 

Hope this helped? If so please upvote.

-- Hope this helps, if so consider leaving some Karma. Even better is if this fixed your issue, that you mark as a solution for others to find. Happy SOARing!! ---

View solution in original post

phanTom
SplunkTrust
SplunkTrust

@stauff there are a few ways to stop this, my main preference is only adding artifacts via methods where you can stipulate run_automation = False. The 3 ways this is possible at the moment are:

  • REST Call to add artifact and set run_automation to False Artifact REST Docs 
  • Use the Phantom Phantom app's add_artifact call and untick the run_automation option
  • Use the extract_ioc action in the Parser app and untick the run_automation 

The issue is that if you add manually to a container then it will NOT provide this option so in this case it would be best to add a tag to the event to state it's been "processed" already and then have a decision at the beginning that looks for that tag and ends if it exists. This can get messy in the activity pane if you are adding a lot manually but will work. 

Personally I would recommend controlling the addition of artifacts by a playbook, maybe with a prompt for artifact info and then use REST or the add_artifact to add the data with the run_automation set to False. 

Hope this helped? If so please upvote.

-- Hope this helps, if so consider leaving some Karma. Even better is if this fixed your issue, that you mark as a solution for others to find. Happy SOARing!! ---
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

The Trust Gap: Why a Data Foundation is Fundamental to an Agentic Enterprise

The Trust Gap: Why a data foundation is fundamental to an  Agentic Enterprise.   Agentic AI is transforming ...

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...

Federated Search for CloudWatch Unified Data Store Is Generally Available

As organizations modernize their cloud environments, AWS workloads generate more security, operational, and ...