Splunk SOAR

Splunk SOAR- Crowdstrike sandbox download report

harishlnu
Engager

Hi Team,

 

Could you please help me on the logic on to download the crowdstrike sandboxed  analysis report using Splunk soar.

Thanks in advance

Regards,

Harisha

Labels (1)
Tags (1)
0 Karma

Tom_Lundie
Contributor

Hi Harisha,

There is an add-on on Splunkbase for this:

CrowdStrike OAuth API | Splunkbase

This SOAR Add-on allows you to download the reports. It might already be installed on your SOAR instance so feel free to check. The first thing you will need to do is configure an asset with the correct API credentials within the Crowdstrike app.

Once you have the app configured you can then implement actions within a playbook to do whatever you need. If you have any specific questions along the way then feel free to ask away!

0 Karma

harishlnu
Engager

@Tom_Lundie 

Thanks for the response.

We have already configured in Splunk soar, and I am not able to download as CSV, Jason,PCAP,STIX.
But requirement is to get all results(including screenshot) as pdf.

Please let me know if you have any suggestion on this

0 Karma

Tom_Lundie
Contributor

Hi,

If you are facing a specific error then please post it here. Otherwise if you just need general guidance then I would start with the documentation:

Create a new playbook in Splunk SOAR (Cloud) - Splunk Documentation

0 Karma

harishlnu
Engager

Hi @Tom_Lundie ,


I am checking is there anyways we can download sandboxing result as pdf.

Regards,

Harisha

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...