Splunk SOAR

How to Read Comments in Playbooks

SOARt_of_Lost
Path Finder

With SOAR 6.1's addition of the "Run automatically when" field, it would be great to be able to run a playbook on container resolution that can read the closure comment. Bonus points if you can explain why Comment data is separate from Event data in the export while notes aren't.

Labels (2)
0 Karma
1 Solution

SOARt_of_Lost
Path Finder

You can read the comments on a container by using the the API in a code or custom function block.

 

comment_url = phantom.build_phantom_rest_url('container', container_id, 'comments')

comment_resp_json = phantom.requests.get(comment_url, verify=False).json()

if comment_resp_json.get('count', 0) > 0:
    phantom.debug(comment_resp_json)

 

You can then parse the comments to your heart's content.

View solution in original post

SOARt_of_Lost
Path Finder

You can read the comments on a container by using the the API in a code or custom function block.

 

comment_url = phantom.build_phantom_rest_url('container', container_id, 'comments')

comment_resp_json = phantom.requests.get(comment_url, verify=False).json()

if comment_resp_json.get('count', 0) > 0:
    phantom.debug(comment_resp_json)

 

You can then parse the comments to your heart's content.

Get Updates on the Splunk Community!

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Community Feedback

We Want to Hear from You! Share Your Feedback on the Splunk Community   The Splunk Community is built for you ...

Manual Instrumentation with Splunk Observability Cloud: Implementing the ...

In our observability journey so far, we've built comprehensive instrumentation for our Worms in Space ...