Splunk SOAR

Updating a lookup in Splunk via a Splunk SOAR playbook

Joei
Engager

Hello everyone,

I am currently working on creating a Splunk SOAR playbook that collects variables from a case and appends them to a Splunk Lookup file (CSV). Unfortunately, I have not been able to find any resources on this topic.

Has anyone had experience with this or can provide guidance?

Thank you for your support !

Labels (2)
0 Karma
1 Solution

Joei
Engager

i managed to fix this via Splunk App on Splunk SOAR , i ran a Custom SPL query that uses "outputlookup" to update an existing lookup file . 

 

View solution in original post

0 Karma

Joei
Engager

i managed to fix this via Splunk App on Splunk SOAR , i ran a Custom SPL query that uses "outputlookup" to update an existing lookup file . 

 

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@Joei- I'm not sure if there is any direct connector for Splunk which updates lookup in Splunk. But here is an alternative you can try if you are a developer or someone in your team is a developer and can create a custom Python playbook in SOAR.

 

Splunk offers rest-endpoint to update the lookup which can be leveraged in Python SOAR Playbook to update the lookup.

https://docs.splunk.com/Documentation/Splunk/9.4.0/RESTREF/RESTknowledge#data.2Flookup-table-files.2...

 

I hope this helps!!! Kindly upvote if it does!!!

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...