Splunk SOAR

Phantom Prompt Block: When using the response type 'list', is there a way to have #1 be set as the default response?

ktsplunksoar
New Member

Not sure if this is a limitation of Phantom prompt block or if someone has figured this out already.

I am using a prompt block to allow a user build up a config file that will eventually be sent to Splunk to create a saved search. The questions allow the user to select specific values for fields to generate the metadata necessary for the splunk saved search (splunk query, time fields, eval fields, etc). 

The response type for the question is a list of choices. There are two choices:

  1. The existing field value (which comes from the config file that was pulled via prior action call)
  2. CHANGE (which would be selected when the value needs to be changed)

When using the response type 'list', is there a way to have #1 be set as the default response? Therefore, you would only have to select CHANGE from the drop down, rather than having to select the existing field's value every time if it doesn't need changed.

Labels (2)
0 Karma

Benni
Loves-to-Learn

As this is still not possible AFAIK, I've created an App, which provides the ability to add custom HTML forms to the Splunk SOAR UI.

https://github.com/Benni0/Phantom-s-Bag-of-Tricks

0 Karma

phantom_mhike
SplunkTrust
SplunkTrust

@ktsplunksoar,
@phanTom 100 percent correct on this whether we are talking about supported or unsupported options. I have tried every version I can think of for hacking together a short circuit in prompts with a default or an auto fill. Without a feature addition, there is no way to do this.

0 Karma

phanTom
SplunkTrust
SplunkTrust

@ktsplunksoar unfortunately ALL prompt responses need to be filled before it will allow progression and there is no "default" setting for prompts at present. 

haleyykidd
Engager

Is this still the case ? Or have there been any changes made that allow a drop down option to be pre-selected?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...