Splunk SOAR

Is there a way to automatically trigger SOAR playbook from S3 file added event?

akitatake
New Member

Hello,

Is there a way to have a playbook automatically trigger when a file is added to an S3 bucket in our AWS account? My initial thought is to have an AWS lambda trigger when a file is added to the S3 bucket, then have that lambda publish the file event information to a kafka topic, then have our Splunk SOAR hooked up to poll that kafka topic via the Kafka SOAR App, then have the playbook set up to trigger when something comes in on that poll (if that's even possible). Is this the best way to go about this?

Thank you!

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...