Splunk SOAR

add data section to an app results

meshorer
Path Finder

hi,

i built an app, when I run the app's action in a playbook, I dont have an option to get the data results.

I used: action_result.add_data()

but it didnt seem to make a difference,

how can I solve it?

Labels (1)
0 Karma

meshorer
Path Finder

Hi @phanTom 

how can I map the output datapaths in the app's JSON file ? Is there any document link or video that can be assistance for that matter?

0 Karma

phanTom
SplunkTrust
SplunkTrust

@meshorer I would really need to see the app code to make any informed advice. The tutorial should have the information you need and within the IDE itself you should be able to see the process outputted when testing the action in the IDE. 

Even if the data is being saved, to see it in a playbook as an output datapath you need to map the output datapaths in the app's JSON file. 

I would look at other apps and try to spot any difference in your code when adding results and also the JSON structure for the action outputs. 

Happy SOARing!

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...