Splunk SOAR

Filter block unable to filter on list input

N_K
Engager

So I've got a list containing multiple strings, depending on these strings I want to run 1 or more actions using a filter. When I use the 'in' filter to check if a certain string is in the list the matching condition is not met. 

Example

input = ['block_ioc', 'reset_password']

Filter block:

N_K_1-1726745040581.png

I can successfully use the 'in' condition in a decision block, just not a filter block. 

 

Any ideas? 

 

Labels (2)
0 Karma

marnall
Motivator

Any reason why it has to be a filter and not a decision block? Do you want it to only match on one condition and ignore the other condition?

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...