Splunk SOAR

Repost: Assign different Label with different use case within the same Asset

AliMaher
Path Finder

Hello SOARians,

I am thinking of a scenario where an external alert from a SIEM like qRadar or Elastic should trigger a playbook. For example, a bruteforce alert should trigger a bruteforce playbook, a portscan alert should trigger a portscan playbook, and so on. Unfortunately, it is only possible to assign the same labels to all incoming SIEM alerts. Based on these labels a playbook is then executed.

Is there any way to assign the labels based on the type (e.g. a field of the alarm) of the incoming alarm or to solve the difference between alarms in another way?

Labels (2)
0 Karma
1 Solution

phanTom
SplunkTrust
SplunkTrust

@AliMaher if you can't create a different label at the creation and time the container in SOAR is created, then the next best approach would be to have a "Landing Playbook" that all the alerts come into and are then sent down the correct path. 

This can be done either by simply connecting the right playbook to the output of a decision, or you can switch the label on the container which will then call the associated active playbook(s) that are set to use that label. 

 

-- Happy SOARing! If this helped please leave some karma. If it resolved the issue please mark as a solution for others to see. --

-- Hope this helps, if so consider leaving some Karma. Even better is if this fixed your issue, that you mark as a solution for others to find. Happy SOARing!! ---

View solution in original post

phanTom
SplunkTrust
SplunkTrust

@AliMaher if you can't create a different label at the creation and time the container in SOAR is created, then the next best approach would be to have a "Landing Playbook" that all the alerts come into and are then sent down the correct path. 

This can be done either by simply connecting the right playbook to the output of a decision, or you can switch the label on the container which will then call the associated active playbook(s) that are set to use that label. 

 

-- Happy SOARing! If this helped please leave some karma. If it resolved the issue please mark as a solution for others to see. --

-- Hope this helps, if so consider leaving some Karma. Even better is if this fixed your issue, that you mark as a solution for others to find. Happy SOARing!! ---
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Note: This post outlines a proposed architecture and serves as an interest check. If we secure commitments ...