Splunk SOAR

Filter block unable to filter on list input

N_K
Engager

So I've got a list containing multiple strings, depending on these strings I want to run 1 or more actions using a filter. When I use the 'in' filter to check if a certain string is in the list the matching condition is not met. 

Example

input = ['block_ioc', 'reset_password']

Filter block:

N_K_1-1726745040581.png

I can successfully use the 'in' condition in a decision block, just not a filter block. 

 

Any ideas? 

 

Labels (2)
0 Karma

marnall
Motivator

Any reason why it has to be a filter and not a decision block? Do you want it to only match on one condition and ignore the other condition?

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...