Splunk SOAR

logging in Splunk SOAR

emesabarrameda
Loves-to-Learn

Hi, 

I am implementing a Splunk SOAR Connector and i was wondering if it is possible to write logs at different levels. There are different levels that can be configured on SystemHealth/Debugging but the BaseConnector only has debug_print and error_print methods. How can I print INFO,  WARNING and TRACE logs on my connector?

Thank

Eduardo

Labels (2)
0 Karma

phanTom
SplunkTrust
SplunkTrust

@emesabarrameda I can't seem to find anything in the docs: https://docs.splunk.com/Documentation/SOARonprem/6.2.0/DevelopApps/AppDevAPIRef 

Both options you call out have the tag option which could maybe be used for thee INFO/WARNING/TRACE strings?

Any reason you want to Split into those categories as it all ends up in spawn.log anyway. 

-- Hope this helps, if so consider leaving some Karma. Even better is if this fixed your issue, that you mark as a solution for others to find. Happy SOARing!! ---
0 Karma

emesabarrameda
Loves-to-Learn

Hi @phanTom 

Thank for your reply.

On my connector,  there are some actions that are repeated a lot and having logs on them could flood the logs. I was hopping to add those logs only if customer chose to enable them.

Why is the reason to have different levels of loggings if we cannot decide whether to print them or not? 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...

Developer Spotlight with Mika Borner

From Hackathon Winner to Enterprise Leader    Mika Borner, CEO and Founder of Datapunctum AG, has been ...

Continue Your Federation Journey: Join Session 3 of the Bootcamp Series

To help practitioners build a stronger foundation, we launched the Data Management & Federation ...