Splunk SOAR

Splunk App for SOAR Export not sending notables when running on a schedule

JJCO
Engager

I have the Splunk App for SOAR Export running.  I can open one of the forwarding events, click "Save and Preview' and send any events into SOAR,  This is working.  

I can go into the Searches, reports, and alerts area find the alert the app created, it's scheduled, running and finding notables.  This is working.

What's not working is when the schedule alert runs, what it finds never gets sent into SOAR.

So, manually sending to SOAR works from the app, the scheduled alert the app uses is running and finding notables, but nothing ever goes into SOAR.  The owner is nobody for all of the searches.  Is this a permissions issue maybe?

0 Karma

churyn_splunk
Splunk Employee
Splunk Employee

Make sure you are setting a valid label for the container.  Also, double check for valid severity and sensitivity being set on container.

 

You can check for errors when Splunk tries to create container in SOAR. Run this SPL:

index=cim_modactions error

0 Karma
Get Updates on the Splunk Community!

New Case Study Shows the Value of Partnering with Splunk Academic Alliance

The University of Nevada, Las Vegas (UNLV) is another premier research institution helping to shape the next ...

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...