Splunk SOAR

How to handle Dynamic Assets in playbooks?

Dave_Burns
Path Finder

Just came across an interesting use case, and I'm wondering how people solve it. 

Phantom talks to an internal asset via HTTP and API key.

This asset has redundancy, and if it goes down a backup comes online. Part of that is name re-direction. The data underneath is all the same but the API key changes. 

My thought would be to perform a test connectivity check at the top of the playbook, and then pass the asset number down the playbook. 

Is there a smarter way to handle this? 

Thanks!

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...