Splunk SOAR

REST query get executed from a playbook

brandyhinton
Loves-to-Learn Lots

Hi All, I am writing a playbook that  sends an automated email when a case is opened in phantom.   I know If you are doing a manual promotion (via GUI), then you would need to have a REST query get executed from a playbook hitting the container endpoint and looking for "container_type": "case".  Then you would just have a format block to populate the REST results and have a connected send email action via SMTP.  what are the steps to get a REST query get executed?

 

Brandy

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes & Cloud Monitoring with Splunk IM

Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team on ...

Index This | What did the zero say to the eight?

June 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

Splunk Observability Cloud's AI Assistant in Action Series: Onboarding New Hires & ...

This is the fifth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...