Splunk SOAR

Splunk App for SOAR Export not sending notables when running on a schedule

JJCO
Engager

I have the Splunk App for SOAR Export running.  I can open one of the forwarding events, click "Save and Preview' and send any events into SOAR,  This is working.  

I can go into the Searches, reports, and alerts area find the alert the app created, it's scheduled, running and finding notables.  This is working.

What's not working is when the schedule alert runs, what it finds never gets sent into SOAR.

So, manually sending to SOAR works from the app, the scheduled alert the app uses is running and finding notables, but nothing ever goes into SOAR.  The owner is nobody for all of the searches.  Is this a permissions issue maybe?

0 Karma

churyn_splunk
Splunk Employee
Splunk Employee

Make sure you are setting a valid label for the container.  Also, double check for valid severity and sensitivity being set on container.

 

You can check for errors when Splunk tries to create container in SOAR. Run this SPL:

index=cim_modactions error

0 Karma
Get Updates on the Splunk Community!

Now Playing: Splunk Education Summer Learning Premieres

It’s premiere season, and Splunk Education is rolling out new releases you won’t want to miss. Whether you’re ...

The Visibility Gap: Hybrid Networks and IT Services

The most forward thinking enterprises among us see their network as much more than infrastructure – it's their ...

Get Operational Insights Quickly with Natural Language on the Splunk Platform

In today’s fast-paced digital world, turning data into actionable insights is essential for success. With ...