Splunk SOAR

How can I run on_poll Ingest Action in SOAR app on a schedule?

anniefry
Engager

I am trying to figure out how to get the on-poll action to run outside of a playbook  to be scheduled in the asset settings under the "ingest setting" tab -- in SOAR on the app page, the ingest setting tab isn't showing up even though I've written an on_poll action within my code. I can run the on_poll action from the app page, but I'm not sure how to run it on a schedule.

Labels (1)
0 Karma
1 Solution

ccl0utier
Splunk Employee
Splunk Employee

Hi @anniefry,

I tested this in my own home lab instance and did a bit of research internally.  The App Wizard apparently does not support adding an on poll action at the moment.  I've asked our documentation team to indicate that in our documentation.

Your best bet is to clone an existing app (say the Splunk or Timer ones) and then use the on poll action that is cloned to create your customized one.

Hope that helps.

View solution in original post

anniefry
Engager

Thank you, as this did help. I used the Timer existing app, within the wizard after choosing a custom action to add for a framework of how to add the action. Then I looked at the json for the existing timer app and thoughtfully borrowed the action entry for on_poll. It's working now.

0 Karma

ccl0utier
Splunk Employee
Splunk Employee

Hi @anniefry,

I tested this in my own home lab instance and did a bit of research internally.  The App Wizard apparently does not support adding an on poll action at the moment.  I've asked our documentation team to indicate that in our documentation.

Your best bet is to clone an existing app (say the Splunk or Timer ones) and then use the on poll action that is cloned to create your customized one.

Hope that helps.

Get Updates on the Splunk Community!

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...