I have the Splunk App for SOAR Export running. I can open one of the forwarding events, click "Save and Preview' and send any events into SOAR, This is working.
I can go into the Searches, reports, and alerts area find the alert the app created, it's scheduled, running and finding notables. This is working.
What's not working is when the schedule alert runs, what it finds never gets sent into SOAR.
So, manually sending to SOAR works from the app, the scheduled alert the app uses is running and finding notables, but nothing ever goes into SOAR. The owner is nobody for all of the searches. Is this a permissions issue maybe?
Make sure you are setting a valid label for the container. Also, double check for valid severity and sensitivity being set on container.
You can check for errors when Splunk tries to create container in SOAR. Run this SPL:
index=cim_modactions error