Splunk SOAR

How to retrieve the full raw object of app action?

CS_
Path Finder

Hey,

Is there a way to retrieve the raw object of an app action in phantom.collect?

So I have an app, which returns the following values:

data, message, status, parameter

And normally that works fine - I can call each of these in turn like this;

 

 

data_result = phantom.collect(container=container, datapath=["my_app_action:action_result.data"])
message_result = phantom.collect(container=container, datapath=["my_app_action:action_result.message"])

 

 

etc.

 

but how do I retrieve the full object? e.g. something like this:

 

 

all_result = phantom.collect(container=container, datapath=["my_app_action:action_result.*"])
all_result = phantom.collect(container=container, datapath=["my_app_action:*"])

 

 


Hope that makes sense.

Labels (1)
Tags (1)
0 Karma
1 Solution

CS_
Path Finder

After a bit more playing around and reading the documentation, i think I've found a way. You just call multiple datapaths at once:

 

paths = ['my_app_action:action_result.data',
'my_app_action:action_result.parameter',
'my_app_action:action_result.summary']

data_result = phantom.collect(container=container, datapath=paths)

 

This returns the values in the 3 datapaths all part of the same list item.

View solution in original post

0 Karma

CS_
Path Finder

After a bit more playing around and reading the documentation, i think I've found a way. You just call multiple datapaths at once:

 

paths = ['my_app_action:action_result.data',
'my_app_action:action_result.parameter',
'my_app_action:action_result.summary']

data_result = phantom.collect(container=container, datapath=paths)

 

This returns the values in the 3 datapaths all part of the same list item.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...