Splunk SOAR

Splunk App for SOAR Export not sending notables when running on a schedule

JJCO
Engager

I have the Splunk App for SOAR Export running.  I can open one of the forwarding events, click "Save and Preview' and send any events into SOAR,  This is working.  

I can go into the Searches, reports, and alerts area find the alert the app created, it's scheduled, running and finding notables.  This is working.

What's not working is when the schedule alert runs, what it finds never gets sent into SOAR.

So, manually sending to SOAR works from the app, the scheduled alert the app uses is running and finding notables, but nothing ever goes into SOAR.  The owner is nobody for all of the searches.  Is this a permissions issue maybe?

0 Karma

churyn_splunk
Splunk Employee
Splunk Employee

Make sure you are setting a valid label for the container.  Also, double check for valid severity and sensitivity being set on container.

 

You can check for errors when Splunk tries to create container in SOAR. Run this SPL:

index=cim_modactions error

0 Karma
Get Updates on the Splunk Community!

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...

AppDynamics is now part of Splunk Ideas

Hello Splunkers, We have exciting news for you! AppDynamics has been added to the Splunk Ideas Portal. Which ...

Advanced Splunk Data Management Strategies

Join us on Wednesday, May 14, 2025, at 11 AM PDT / 2 PM EDT for an exclusive Tech Talk that delves into ...