Splunk SOAR

View history of same containers

meshorer
Path Finder

Hello, 

1. Is there an option (built in or manually built) for a container to view history of the older containers with the same artifacts and details ? It can make an analyst work easier to see notes and how the older case was solved. 

2. by enabling “logging” for a playbook, where opt logs are stored to access later on (beside vie debugging in the UI..)

 

thank you in advance!

Labels (1)
0 Karma

phanTom
SplunkTrust
SplunkTrust

@meshorer there isn't anything inbuilt, but there is a Custom Function in the community Repo called "find_related_containers" which should get you somewhere close to what you want. TBH I would recommend building your own but it can be complicated depending on how you want to define "relevant" containers. 

As for the playbook logs, I am not sure where they are on-disk. I can't see anything in $PHANTOM_HOME/var/log/phantom but suspect they are somewhere on the system. 

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...