I need my Phantom playbook to be able to close a Splunk ES notable event when it's completed, this requires the event_id field which is not included in the artifact when using the adaptive response.
Has anyone found a clever solution?
This is possible when using the Phantom app for Splunk, however we need to pivot and start using the AR
... View more