Splunk SOAR

Multiple Artifacts Causing Multiple Playbook Runs

cmg
Explorer

When a container is created that contains multiple artifacts from a forwarded Splunk event, I noticed playbooks are running against every artifact that has been added, causing duplicate actions.

Reading through the boards here a bit a possible solution was adding logic to check for a container tag on run. Use a decision block to see if a tag exists, if so simply end, otherwise continue and add a tag when complete.

My problem is this appears to work when testing against existing containers (debug against existing container ID and all artifacts), but when a new container is created it seems to ignore this and run multiple times.

My guess is the playbook is being run concurrently for each of the artifacts instead of one at a time.

1. What is causing the problem?
2. What is best practice to prevent this from occurring?

Labels (1)
0 Karma

phanTom
SplunkTrust
SplunkTrust

@cmg it sounds like you are getting multiple artifacts in your container upon creation? If there are duplicate actions does that also mean there are duplicate artifact values? 

There is a setting in the Splunk App for SOAR Export that will create just 1 artifact rather than multiple duplciates where generally only 1 field is different (if there are Multi Value fields in the results). 

-- Hope this helps, if so consider leaving some Karma. Even better is if this fixed your issue, that you mark as a solution for others to find. Happy SOARing!! ---
0 Karma

cmg
Explorer

@phanTom 

Correct, multiple artifacts in a container upon creation. It looks like there are duplicate values, however the artifact ID is different.

I do have multi-value fields configured (default). Is that where you are suggesting making the change?

0 Karma

phanTom
SplunkTrust
SplunkTrust

@cmg yes you should change the setting but be aware values, where there is an MV field,  will now come in as lists and you may need to adjust your playbook(s) to handle that. 

-- Hope this helps, if so consider leaving some Karma. Even better is if this fixed your issue, that you mark as a solution for others to find. Happy SOARing!! ---
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...