Splunk SOAR

Playbook stops in between without completing

shaquibk
Explorer

Hi All,

I am quite new to Phantom. I have written few plabooks which works perfectly as intended when run from the debugger. However, the issue is that, when the playbooks are called via automation, the playbooks start executing but stops in between before getting completed. There are error/warnings seen in the container.

How is that the playbook runs fine when called manually from debugger but not when called by automation.

Any leads would be appreciated.

Thanks,

Shaquib

Labels (1)
0 Karma
1 Solution

phanTom_old
SplunkTrust
SplunkTrust

@shaquibk it would be nice to have visibility of any errors in the container. 

A couple of things can cause what you are seeing:
- Scope
- Badly configured filter

Scope: If you run a playbook against a container once it will see all artifacts, if you run again on the same container without changing the scope, it will only see "New" artifacts so may complain about empty parameters

Filter: IF you just use a filter without a decision in-front and NONE of the conditions are met then it will stop with no indication.

As you say there are errors you see it is unlikely the filter one but until I can see one or more of the errors I am a bit blind. If you can paste the errors here I might be able to better point you to resolution. 

View solution in original post

0 Karma

shaquibk
Explorer

Hey @phanTom_old 

Thanks for the quick response. My issue is now resolved.

The issue was actually due to badly configured filter. Removing it worked.

Thanks,

Shaquib

0 Karma

phanTom_old
SplunkTrust
SplunkTrust

@shaquibk it would be nice to have visibility of any errors in the container. 

A couple of things can cause what you are seeing:
- Scope
- Badly configured filter

Scope: If you run a playbook against a container once it will see all artifacts, if you run again on the same container without changing the scope, it will only see "New" artifacts so may complain about empty parameters

Filter: IF you just use a filter without a decision in-front and NONE of the conditions are met then it will stop with no indication.

As you say there are errors you see it is unlikely the filter one but until I can see one or more of the errors I am a bit blind. If you can paste the errors here I might be able to better point you to resolution. 

0 Karma
Get Updates on the Splunk Community!

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...