Splunk SOAR

Help with Display Extracted List Items Vertically in Format Block

Sidpet
Loves-to-Learn

Hi all,

I have a playbook where I extract multiple rule titles from an ES investigation.  Currently, the data shows like this in the results 

Rule Title: 2 items

0: item 1

1: item 2

when I extract it and create a servicenow ticket it shows the items like this ['item 1', 'item 2'].  I want them to be displayed like they show in the results vertically one item below the other and without the brackets. I tried the %% 

{0}

%% but it does not work. any ideas to help resolve this? 

I’m using SOAR version 6.4.x. Any guidance or best practices would be appreciated. still a novice learning the tool.

Thanks!

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...