Splunk SOAR

Playbook scheduling without containers

drew19
Path Finder

Is there a way to schedule a playbook run without having any container? Is it possible?

Labels (1)
Tags (1)
0 Karma
1 Solution

phanTom
SplunkTrust
SplunkTrust

@drew19 A playbook always needs a container, but if you need playbooks to run without an "Alert" creating the container, the Phantom Timer app (here) will create empty containers on a schedule with a selected label defined. Any active playbooks against that label will then pick this up when created and process as per usual.

View solution in original post

phanTom
SplunkTrust
SplunkTrust

@drew19 A playbook always needs a container, but if you need playbooks to run without an "Alert" creating the container, the Phantom Timer app (here) will create empty containers on a schedule with a selected label defined. Any active playbooks against that label will then pick this up when created and process as per usual.

drew19
Path Finder

Thank you! ❤️ 

Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...