Splunk SOAR

Filter block unable to filter on list input

N_K
Loves-to-Learn Lots

So I've got a list containing multiple strings, depending on these strings I want to run 1 or more actions using a filter. When I use the 'in' filter to check if a certain string is in the list the matching condition is not met. 

Example

input = ['block_ioc', 'reset_password']

Filter block:

N_K_1-1726745040581.png

I can successfully use the 'in' condition in a decision block, just not a filter block. 

 

Any ideas? 

 

Labels (3)
0 Karma

marnall
Motivator

Any reason why it has to be a filter and not a decision block? Do you want it to only match on one condition and ignore the other condition?

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...