Splunk SOAR

logging in Splunk SOAR

emesabarrameda
Loves-to-Learn

Hi, 

I am implementing a Splunk SOAR Connector and i was wondering if it is possible to write logs at different levels. There are different levels that can be configured on SystemHealth/Debugging but the BaseConnector only has debug_print and error_print methods. How can I print INFO,  WARNING and TRACE logs on my connector?

Thank

Eduardo

Labels (2)
0 Karma

phanTom
SplunkTrust
SplunkTrust

@emesabarrameda I can't seem to find anything in the docs: https://docs.splunk.com/Documentation/SOARonprem/6.2.0/DevelopApps/AppDevAPIRef 

Both options you call out have the tag option which could maybe be used for thee INFO/WARNING/TRACE strings?

Any reason you want to Split into those categories as it all ends up in spawn.log anyway. 

0 Karma

emesabarrameda
Loves-to-Learn

Hi @phanTom 

Thank for your reply.

On my connector,  there are some actions that are repeated a lot and having logs on them could flood the logs. I was hopping to add those logs only if customer chose to enable them.

Why is the reason to have different levels of loggings if we cannot decide whether to print them or not? 

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...