Splunk SOAR

How to Read Comments in Playbooks

SOARt_of_Lost
Path Finder

With SOAR 6.1's addition of the "Run automatically when" field, it would be great to be able to run a playbook on container resolution that can read the closure comment. Bonus points if you can explain why Comment data is separate from Event data in the export while notes aren't.

Labels (2)
0 Karma
1 Solution

SOARt_of_Lost
Path Finder

You can read the comments on a container by using the the API in a code or custom function block.

 

comment_url = phantom.build_phantom_rest_url('container', container_id, 'comments')

comment_resp_json = phantom.requests.get(comment_url, verify=False).json()

if comment_resp_json.get('count', 0) > 0:
    phantom.debug(comment_resp_json)

 

You can then parse the comments to your heart's content.

View solution in original post

SOARt_of_Lost
Path Finder

You can read the comments on a container by using the the API in a code or custom function block.

 

comment_url = phantom.build_phantom_rest_url('container', container_id, 'comments')

comment_resp_json = phantom.requests.get(comment_url, verify=False).json()

if comment_resp_json.get('count', 0) > 0:
    phantom.debug(comment_resp_json)

 

You can then parse the comments to your heart's content.

Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...