Splunk SOAR

Updating a lookup in Splunk via a Splunk SOAR playbook

Joei
Engager

Hello everyone,

I am currently working on creating a Splunk SOAR playbook that collects variables from a case and appends them to a Splunk Lookup file (CSV). Unfortunately, I have not been able to find any resources on this topic.

Has anyone had experience with this or can provide guidance?

Thank you for your support !

Labels (2)
0 Karma
1 Solution

Joei
Engager

i managed to fix this via Splunk App on Splunk SOAR , i ran a Custom SPL query that uses "outputlookup" to update an existing lookup file . 

 

View solution in original post

0 Karma

Joei
Engager

i managed to fix this via Splunk App on Splunk SOAR , i ran a Custom SPL query that uses "outputlookup" to update an existing lookup file . 

 

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@Joei- I'm not sure if there is any direct connector for Splunk which updates lookup in Splunk. But here is an alternative you can try if you are a developer or someone in your team is a developer and can create a custom Python playbook in SOAR.

 

Splunk offers rest-endpoint to update the lookup which can be leveraged in Python SOAR Playbook to update the lookup.

https://docs.splunk.com/Documentation/Splunk/9.4.0/RESTREF/RESTknowledge#data.2Flookup-table-files.2...

 

I hope this helps!!! Kindly upvote if it does!!!

Get Updates on the Splunk Community!

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Community Feedback

We Want to Hear from You! Share Your Feedback on the Splunk Community   The Splunk Community is built for you ...

Manual Instrumentation with Splunk Observability Cloud: Implementing the ...

In our observability journey so far, we've built comprehensive instrumentation for our Worms in Space ...