Splunk SOAR

Splunk SOAR
Community Activity
hmvs
Hi Team, Do we have IntelliSense editor support in Phantom Playbook editor in the browser, OR can we integrate existi...
by hmvs Engager in Splunk SOAR 01-18-2022
1 0
1
0
brandyhinton
Hi All, I am writing a playbook that  sends an automated email when a case is opened in phantom.   I know If you are ...
by brandyhinton Loves-to-Learn Lots in Splunk SOAR 01-12-2022
0 0
0
0
iamraprap
I have multiple artifacts and there is a check box beside it. Is there a datapath to access the currently selected ar...
by iamraprap Observer in Splunk SOAR 01-12-2022
0 5
0
5
andrew_burnett
When I try to create a Shared Services server (for a development environment), it prompts me for the password for the...
by andrew_burnett Path Finder in Splunk SOAR 01-07-2022
1 8
1
8
HosamShafikLXT
Dear Splunk team I hope everything is well with you I am writing this post to inform you that I tried to sign up at S...
by HosamShafikLXT New Member in Splunk SOAR 01-04-2022
0 0
0
0
rgrWeidner
Recently upgraded to SOAR 5.0.1from Phantom 4.10 and I'm having some difficulty finding the old "API" actions that ca...
by rgrWeidner Engager in Splunk SOAR 01-04-2022
0 1
0
1
Qingguo
when inputing a customer field of data/time in container,  is there any ways to do hints of input and input validatio...
by Qingguo Engager in Splunk SOAR 12-13-2021
0 1
0
1
Qingguo
Failure to open phantom (4.10.x)  GUI after setting up warm/standby ,   no error message when setup warm/standby and ...
by Qingguo Engager in Splunk SOAR 12-10-2021
0 0
0
0
dmw
Hey everyoneIf an event is added to a case as evidence, it's simple to retrieve it while looking at the case:Sources ...
by dmw New Member in Splunk SOAR 12-08-2021
0 3
0
3
aiyede
Hi, I recently ran into a problem where playbook runs a workflow for a long time (usually hours) without stopping its...
by aiyede Engager in Splunk SOAR 11-30-2021
0 0
0
0
alexander5654
Hi, my team is preparing to upgrade our phantom instance to the newest version, and I had a question regarding the ba...
by alexander5654 New Member in Splunk SOAR 11-30-2021
0 3
0
3
Qingguo
Hi teamI found main flow will not run after adding branch flow ,  is it known limitation ? thanks
by Qingguo Engager in Splunk SOAR 11-17-2021
0 1
0
1
dmw
Hey all. We're evaluating Splunk SOAR and are looking at highly automated configuration management. Part of the setup...
by dmw New Member in Splunk SOAR 11-16-2021
0 0
0
0
nareerat_pr
Hi, I'm using phantom v4.10.3.51237 and my VA team found a security vulnerability that is "nginx Byte Memory Overwrit...
by nareerat_pr Explorer in Splunk SOAR 11-16-2021
0 1
0
1
hiahiahia
I've just installed Phantom software according to link text. My operating system is Centos 7. But I don't know what's...
by hiahiahia Explorer in Splunk SOAR 11-14-2021
0 5
0
5
knot9
I'm configuring the SOAR/Phantom app - Splunk HTTP. I've set it up to use OAuth, provided the authentication URL and ...
by knot9 Engager in Splunk SOAR 11-09-2021
0 0
0
0
samimbarek
Hello,I have a fairly short question.In the classic editor this worked just fine but in the modern one it simply does...
by samimbarek New Member in Splunk SOAR 10-29-2021
0 0
0
0
brandylee19931
I am trying to create a playbook where the first step is a manual block an email address  in the restricted users por...
by brandylee19931 Observer in Splunk SOAR 10-27-2021
0 0
0
0
ponqersohn
Hi,Say we have an action (lets call it Action1) that returns this under data:[{"type": "type1", "target": "target val...
by ponqersohn New Member in Splunk SOAR 10-18-2021
0 0
0
0
EdgeSync
Hi all,Is there any app, method or guidance for ingesting emails directly form a O365 mailbox?So a use case for us wo...
by EdgeSync Engager in Splunk SOAR 10-08-2021
0 2
0
2
EdgeSync
Hey there,I am looking to Configure the Crowdstrike OAuth API app inside my SOAR instance. To connect to Crowdstrike ...
by EdgeSync Engager in Splunk SOAR 10-08-2021
0 1
0
1
shaquibk
Hi Team,I want to know if it is possible pass data present in a format block of one playbook to another playbook bein...
by shaquibk Explorer in Splunk SOAR 09-23-2021
0 1
0
1
bongo
How can you delete reports that have been created on the /reports page?I have administrator rights but can't see any ...
by bongo Explorer in Splunk SOAR 09-08-2021
1 3
1
3
dewu94
I am trying to search for MISP events by their name, which is present in 'info' field. For this purpose I'm using 'ot...
by dewu94 Explorer in Splunk SOAR 09-08-2021
0 6
0
6
dphegarty
I am attempting to use the "Run Query" action from the Phantom MISP app. PARAMETER REQUIRED DESCRIPTION TYPE ...
by dphegarty New Member in Splunk SOAR 09-07-2021
0 2
0
2
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...