Splunk SOAR

Is there a way for us to check/test connectivity across a list of assets from within a playbook?

nongingerale
Explorer

Hi all - is there a way for us to check/test connectivity across a list of assets from within a playbook? I was looking through the documentation and haven't found information that says it is possible or not. I only see how to do it manually or with the rest api call app_status but no examples on how to use it within a playbook. Any help is appreciated!

0 Karma

phanTom
SplunkTrust
SplunkTrust

@nongingerale 

The 2 ways to get REST data in a playbook and use it are:

1. HTTP App 
2. phantom.requests.get()

You may have to jump through some other REST hoops to get what you want as the asset_status results have their own id with the asset_id as a field so you need to get the asset_id first. Then query asset_status to grab the data for the asset(s) you want to check. Then work out if the status is "success" or "failed" then <do something>

Personally I would use the phantom.requests.get() for this as it will give you more control and not make you need multiple playbook blocks. 

https://docs.splunk.com/Documentation/SOARonprem/6.0.2/PlaybookAPI/SessionAPI 

0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...