Splunk SOAR

Filter block unable to filter on list input

N_K
Engager

So I've got a list containing multiple strings, depending on these strings I want to run 1 or more actions using a filter. When I use the 'in' filter to check if a certain string is in the list the matching condition is not met. 

Example

input = ['block_ioc', 'reset_password']

Filter block:

N_K_1-1726745040581.png

I can successfully use the 'in' condition in a decision block, just not a filter block. 

 

Any ideas? 

 

Labels (2)
0 Karma

marnall
Motivator

Any reason why it has to be a filter and not a decision block? Do you want it to only match on one condition and ignore the other condition?

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...