Splunk SOAR

How to do hint and input validation for custom field in phantom

Qingguo
Engager

when inputing a customer field of data/time in container,  is there any ways to do hints of input and input validation  ? 

Currently it only support text/select in 4.10.X in customer field ,   and it is not real-time if done by playbook or some action.

Labels (1)
0 Karma

phanTom
SplunkTrust
SplunkTrust

@Qingguo at the moment the only way to control this is to have a playbook with a prompt for the person inputting the time stamp, then you can validate the prompt entry with a little bit of custom code in the playbook. If valid, add to the custom_field else either ask again in the same playbook or fail and inform the user that they inputted an incorrect date and they should re-run the playbook. 

I have done this at a few customers now. 

0 Karma
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...