Splunk SOAR

How to handle Dynamic Assets in playbooks?

Dave_Burns
Path Finder

Just came across an interesting use case, and I'm wondering how people solve it. 

Phantom talks to an internal asset via HTTP and API key.

This asset has redundancy, and if it goes down a backup comes online. Part of that is name re-direction. The data underneath is all the same but the API key changes. 

My thought would be to perform a test connectivity check at the top of the playbook, and then pass the asset number down the playbook. 

Is there a smarter way to handle this? 

Thanks!

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...