Splunk SOAR

Splunk connector version 2.14 in SOAR 6.0 Error

uditdasgupta
Loves-to-Learn Everything

I am trying to query a Splunk search head using the Splunk connector from SOAR. However, my playbook is giving an error in the action block with the below error:

Failed to connect to splunk server. HTTP Error 400: Bad Request (1235)

There are no issues of connectivity as I have tested the connectivity to our asset in the app and it has passed successfully.

Yet, my playbook is failing with the above error.

My playbook design consists of a format block that formats the simple SPL query as :

|makeresults|eval id="This is a test" |eval playbook="App upgrade splunk"|table _time id playbook

which is referenced in the action block that queries a Splunk Search Head using the Splunk app.

Any advise on the possible issue is much appreciated ?

Thanks in advance

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...

What's New in Splunk Observability - October 2025

What’s New?    We’re excited to announce the latest enhancements to Splunk Observability Cloud and share ...