Splunk SOAR

Setting event status to close when playbook is triggered by case

shangxuan_shi
Explorer

I have promote multiple events into a case. From the case, I will run a playbook. 

I understand that I can use the following container automations to set the status to close.

  1. phantom.update()
  2. phantom.close()
  3. phantom.set_status()

However, these 3 playbook is only able to set the case's status to close. Is it possible to set the status of the promoted events within the case to close also? 


For example, I have the following events.

  • Event #1
  • Event #2
  • Event #3

When these 3 events are promoted to a case. And I run the playbook from this case, is it possible to set the status of this case and the 3 events to close . 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...