Splunk SOAR

copy an artifact existing in one event into an existing case or place event as a "child" of an open case

MikeR
New Member

I am working on a playbook where there is a need to copy the current event's artifacts  into a separate open and existing case.  We are looking for a way to automate this through phantom.collect +  phantom.add_artifact or other means. We have a way to pass in the existing case id  and need a solution to duplicate atrifacts from running event into that case specified by case id. 

Labels (2)
Tags (1)
0 Karma

MikeR
New Member

@phanTom 

We ended up using custom function with phantom.merge() as this fit our needs and was very simple (few lines of code). We also found how to use phantom.collect() to read in everything after some trial and error. Thank you for pointing out the addon app 

0 Karma

phanTom
SplunkTrust
SplunkTrust

@MikeR a few ways to achieve this, but simplest is probably to use the Phantom Phantom app with the 'add_artifact' action. This will use phantom.collect() and if you set the container input to the id of the other container it will update it with the provided artifact info provided in the action and should  return an id. 

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...