Splunk SOAR

Splunk App for SOAR Export not sending notables when running on a schedule

JJCO
Engager

I have the Splunk App for SOAR Export running.  I can open one of the forwarding events, click "Save and Preview' and send any events into SOAR,  This is working.  

I can go into the Searches, reports, and alerts area find the alert the app created, it's scheduled, running and finding notables.  This is working.

What's not working is when the schedule alert runs, what it finds never gets sent into SOAR.

So, manually sending to SOAR works from the app, the scheduled alert the app uses is running and finding notables, but nothing ever goes into SOAR.  The owner is nobody for all of the searches.  Is this a permissions issue maybe?

0 Karma

churyn_splunk
Splunk Employee
Splunk Employee

Make sure you are setting a valid label for the container.  Also, double check for valid severity and sensitivity being set on container.

 

You can check for errors when Splunk tries to create container in SOAR. Run this SPL:

index=cim_modactions error

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Brett Adams

In our third Spotlight feature, we're excited to shine a light on Brett—a Splunk consultant, innovative ...

Index This | What can you do to make 55,555 equal 500?

April 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...