Hi everyone, I’m having an issue with the integration between Splunk Enterprise and Splunk SOAR. I have configured Splunk to send alerts/notable events to SOAR, and the integration appears to be working, but some alerts are not being sent to SOAR. It seems to happen intermittently, especially when the alert volume increases. Has anyone experienced this issue? I’d like to understand: Are there any limits on how many alerts Splunk can send to SOAR? Is there a queue, throttling, or rate limit that could cause alerts to be dropped? How can I check whether Splunk is actually attempting to send the alert? Are there specific Splunk logs I should check for failed deliveries? Is there a setting to make Splunk send all matching alerts without limiting or suppressing them? How can I configure the alerting/integration so that alerts are not silently missed? Any guidance on troubleshooting this would be appreciated. If you need more information about my Splunk/SOAR versions or integration configuration, I can provide them. Thanks. update: i get this error to: signature="Unable to create container: __all__: A container with the same source_data_identifier already exists for this asset and label! Containers need to have unique source_data_identifier per asset and label." signature="Posted to KV store for retry later: True. content: b'{key":"0"}'
... View more