Splunk SOAR

How to Trigger a Splunk SOAR Playbook on a schedule?

rgrWeidner
Engager

I want to trigger a Splunk SOAR playbook to iterate through a list of hosts every hour and check if they are online in our EDR tool, and if they are online to display a message to the user via the EDR API. Although the playbook is already complete, I can't think of a good way to have it execute every hour. I thought about using a Splunk app ingestion to query our Splunk instance every 60 minutes to create a dummy label and container that the playbook could be set to "active" on, but that seems like an awkward work around. 

 

Is there some other app or setting I'm missing that could achieve this goal?

 

Labels (2)
0 Karma
1 Solution

CS_
Path Finder

I've seen an answer to this before, because I wanted to do the exact same thing. There's no setting or kind of intuitive way to do it.

However in this post it details a way to accomplish it, and it works fairly well.

https://community.splunk.com/t5/Splunk-SOAR-f-k-a-Phantom/How-to-schedule-a-Phantom-playbook-to-run-...



View solution in original post

phanTom
SplunkTrust
SplunkTrust

@rgrWeidner , @CS_ is correct in pointing you to that article! 

Using the timer app you can create containers on  a schedule with a label and title. If you have a playbook set to active for the label you choose then it will run when the timer app creates the container. 

0 Karma

CS_
Path Finder

I've seen an answer to this before, because I wanted to do the exact same thing. There's no setting or kind of intuitive way to do it.

However in this post it details a way to accomplish it, and it works fairly well.

https://community.splunk.com/t5/Splunk-SOAR-f-k-a-Phantom/How-to-schedule-a-Phantom-playbook-to-run-...



Get Updates on the Splunk Community!

Fueling your curiosity with new Splunk ILT and eLearning courses

At Splunk Education, we’re driven by curiosity—both ours and yours! That’s why we’re committed to delivering ...

Splunk AI Assistant for SPL 1.1.0 | Now Personalized to Your Environment for Greater ...

Splunk AI Assistant for SPL has transformed how users interact with Splunk, making it easier than ever to ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureOn Demand Now Step boldly into the AI revolution with enhanced security ...