Splunk Tech Talks
Deep-dives for technical practitioners.

Adaptable Incident Response with Splunk Phantom Modular Workbooks

melissap
Splunk Employee
Splunk Employee

View our Tech Talk: Security Edition,  Adaptable Incident Response with Splunk Phantom Modular Workbooks 

Phantom Workbooks allow you to codify your security standard operating procedures into reusable templates. Phantom supports custom and industry-standard workbooks that allow you to divide tasks into phases, assign responsibilities to team members, and document your work. However, no single end-to-end workbook can be a “one size fits all” for every investigation of a particular security incident. For instance, one phishing workbook cannot be expected to capture every possible permutation of tasks for every phishing investigation. Some real-time task modification may be required to adapt to unforeseen circumstances in the case. 

 That’s why we created “modular workbooks” that allow you to effortlessly adapt your security operations workflow. Rather than trying to create all-encompassing end-to-end workbooks that strictly define every single task, modular workbooks allow you to create task modules and combine them in different ways to complete your investigation process. This not only enables more dynamic run-time assignment, but makes workbooks more adaptable and scalable across a variety of use cases. 

Tune in to this Tech Talk to:

  • Learn how Phantom can dynamically add tasks to your workbooks
  • Understand why workbooks might need to adapt during investigations
  • See modular workbook development in action and utilize these examples in your organization

Tech Talks conversations will live for two weeks after the talk. You can then continue the conversation in the tag Phantom on Splunk Answers.

melissap
Splunk Employee
Splunk Employee

Sharing a question from the live tech talk.

Q: Sorry, where do you put the block of the custom function that decide which piece of workbook to add?

A: In Phantom 4.9 if you go to the the Admin drop-down, then 'playbooks' there is a 'custom functions' tab where you can build those out

nen
New Member

@melissap It will be good if workbooks have validation like if certain tasks are completed in workbook than only user can close the case /event in phantom. right now we can not impose user to perform certain task in workbook. I think this is major missing with respect to wookbooks

melissap
Splunk Employee
Splunk Employee

@nen Thanks for this feedback.  I connected with the product team and they informed me they are working on a new, more robust feature. The timing is still TBD, but we will be sure to have updates when it becomes available.

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...