Activity Feed
- Posted Update Splunk notables from Splunk Soar on Splunk Enterprise. 05-17-2024 08:51 AM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
0 |
05-17-2024
08:51 AM
Hi Team, is it possible to update/enrich a notable after executing a playbook in splunk soar and that execution output must be attached in the Splunk notable. Example: Assume I have correlation search named one and this triggers a notable and run a playbook actions. Now once the search triggers and notable is created, the action run a playbook should execute in soar and attach that output to the notable created. You think of this attaching ip reputation/geo locations of an ip to the notable so that soc can work without logging into virus total or any other sites. Thank you
... View more
Labels
- Labels:
-
using Splunk Enterprise