Splunk SOAR

Splunk SOAR
Community Activity
geekf
I installed the Splunk App for SOAR Export app on Splunk, and I can see two alert options in manage alerts, namely 'R...
by geekf Path Finder in Splunk SOAR 07-26-2022
0 0
0
0
TamishaJ
Have anyone ran across the following issue before?  I am trying to implement the Splunk SOAR app but we are not able ...
by TamishaJ Engager in Splunk SOAR 07-26-2022
0 1
0
1
Dave_Burns
Hoping someone can help me get past the last hurdle. I'm trying to create a custom function that dynamically calls ot...
by Dave_Burns Path Finder in Splunk SOAR 07-25-2022
0 1
0
1
djacquens
Hi,We need to use a preprocess script for the Crowdstrike APP but don't manage to have it working. We are interested ...
by djacquens Path Finder in Splunk SOAR 07-22-2022
0 2
0
2
jeffminkah20
Am trying to access Crowdstrike Intel endpoint where oauth2 token is needed. When I test asset connectivity, I get be...
by jeffminkah20 Observer in Splunk SOAR 07-21-2022
0 3
0
3
joconnor
I've created an alert in Splunk Enterprise and used the Splunk SOAR / Phantom plugin to call the action "Run a playbo...
by joconnor Explorer in Splunk SOAR 07-21-2022
0 3
0
3
Gewch
Hello, We currently utilize the Windows Defender ATP v 3.6.0 app in our Splunk SOAR Cloud instance.  I've discovered ...
by Gewch Engager in Splunk SOAR 07-20-2022
0 3
0
3
GeorgeOrwell
I have two actions linked together.The first one is a block with custom code where I want to list all of the files in...
by GeorgeOrwell Explorer in Splunk SOAR 07-19-2022
0 5
0
5
yw_soar
Hi all, I have a use case where i need to check for duplicate JIRA contents Basically, we are ingesting our JIRA into...
by yw_soar New Member in Splunk SOAR 07-19-2022
0 0
0
0
sdintino_splunk
Hi All, ServiceNow supports multiple ticket types such as "RITM", "SCTASK", "INCIDENT".  Our Splunk Cloud instance to...
by sdintino_splunk Splunk Employee Splunk Employee in Splunk SOAR 07-15-2022
0 2
0
2
rwahidur2
Hi,I have registered for Splunk Phantom Community edition download 3 days ago. However, still the approval is pending...
by rwahidur2 New Member in Splunk SOAR 07-14-2022
0 1
0
1
GeorgeOrwell
I would like to run my playbooks after the changes have been introduced without making commit messages 
by GeorgeOrwell Explorer in Splunk SOAR 07-14-2022
0 1
0
1
GeorgeOrwell
I'm looking for a way to collect all custom lists.  While I can do so individually for every Custom List with `phanto...
by GeorgeOrwell Explorer in Splunk SOAR 07-11-2022
0 1
0
1
GeorgeOrwell
So, I'm looking for a way to synchronize Custom Lists to git the same way Playbooks and Custom Functions are synchron...
by GeorgeOrwell Explorer in Splunk SOAR 07-06-2022
0 1
0
1
CS_
Hey all, So I have some playbooks which were working fine previously, but I don't know if something has changed on SO...
by CS_ Path Finder in Splunk SOAR 07-04-2022
0 2
0
2
goncalocoelho
Hi All, is it possible to retrieve the (splunk soar) instance details inside a playbook? For instance when sending an...
by goncalocoelho Path Finder in Splunk SOAR 06-29-2022
0 2
0
2
wisconsin
When scanning an endpoint in SOAR how to you get a credential scan? I can start a scan via SOAR playbook but its not ...
by wisconsin New Member in Splunk SOAR 06-29-2022
0 1
0
1
ss008i
Hello, I am trying to find a native solution in order to monitor the execution of a Phantom Playbook. In case one of ...
by ss008i Engager in Splunk SOAR 06-29-2022
0 2
0
2
soumyasaha25
i have Multiple event forwardings enabled on my Phantom App for Splunk that use saved searches to trigger notable eve...
by soumyasaha25 Contributor in Splunk SOAR 06-27-2022
0 3
0
3
saurabhpati
Hi Community, Could any of you please let me know if there is any way or pre written app to connect Azure Sentinal wi...
by saurabhpati New Member in Splunk SOAR 06-21-2022
0 0
0
0
CS_
In a playbook, I have a decision tree.If option A -> Check List -> If Value Exists in custom list -> Do NothingElse I...
by CS_ Path Finder in Splunk SOAR 06-21-2022
0 2
0
2
shanto12
I was wondering if anyone has experience installing the AB on a virtual machine? Is this possible? What are the chall...
by shanto12 New Member in Splunk SOAR 06-21-2022
0 1
0
1
jeffrey_berry
In our environment (Phantom version 4.10.3.x), the HEC (HTTP Event Collector) server name that is used as an "Indexer...
by jeffrey_berry Path Finder in Splunk SOAR 06-20-2022
0 0
0
0
rgrWeidner
I want to trigger a Splunk SOAR playbook to iterate through a list of hosts every hour and check if they are online i...
by rgrWeidner Engager in Splunk SOAR 06-18-2022
0 2
0
2
CS_
I'm interested in suggestions on how to tackle this. I know how I would implement it in Python, but not really sure b...
by CS_ Path Finder in Splunk SOAR 06-17-2022
0 2
0
2
Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...