Splunk SOAR

Updating a lookup in Splunk via a Splunk SOAR playbook

Joei
Engager

Hello everyone,

I am currently working on creating a Splunk SOAR playbook that collects variables from a case and appends them to a Splunk Lookup file (CSV). Unfortunately, I have not been able to find any resources on this topic.

Has anyone had experience with this or can provide guidance?

Thank you for your support !

Labels (2)
0 Karma
1 Solution

Joei
Engager

i managed to fix this via Splunk App on Splunk SOAR , i ran a Custom SPL query that uses "outputlookup" to update an existing lookup file . 

 

View solution in original post

0 Karma

Joei
Engager

i managed to fix this via Splunk App on Splunk SOAR , i ran a Custom SPL query that uses "outputlookup" to update an existing lookup file . 

 

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@Joei- I'm not sure if there is any direct connector for Splunk which updates lookup in Splunk. But here is an alternative you can try if you are a developer or someone in your team is a developer and can create a custom Python playbook in SOAR.

 

Splunk offers rest-endpoint to update the lookup which can be leveraged in Python SOAR Playbook to update the lookup.

https://docs.splunk.com/Documentation/Splunk/9.4.0/RESTREF/RESTknowledge#data.2Flookup-table-files.2...

 

I hope this helps!!! Kindly upvote if it does!!!

Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...