Splunk SOAR

Has anyone ever reassigned SOAR objects between users?

victor_menezes
Communicator

Hi folks,

I'm evaluating a situation related to enabling SAML auth on SOAR but earlier I was using local accounts. Because of that, objects like assets, playbooks, etc are currently tied to the local user ids, and SAML users have different user ids. I'm looking for ideas on how to update that ownership from local to SAML new user id in order to have the users still owning those objects after changing their login type.

Or, another option but that will be unlikely to be something doable, but if I could have the SAML login to use the same user id as the local (like one replace the other) would also be interesting to explore.

Labels (3)
Tags (3)
0 Karma

phanTom
SplunkTrust
SplunkTrust

@victor_menezes the way I would do this is to use REST. 

1. Go to /rest/ph_user and filter for the user ids of the old and new user
2. Find all "items" owned by the old user in the relevant REST endpoint
3. Write a custom function / code block to loop through the found items and update the user id value via POST

REST Docs: https://docs.splunk.com/Documentation/SOARonprem/5.5.0/PlatformAPI/Using 

Use the phantom.requests() for local REST Calls: https://docs.splunk.com/Documentation/SOARonprem/5.5.0/PlaybookAPI/SessionAPI 

 

-- Hope this helped? If so please mark as a solution. Happy SOARing! --

-- Hope this helps, if so consider leaving some Karma. Even better is if this fixed your issue, that you mark as a solution for others to find. Happy SOARing!! ---
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...