Splunk SOAR

Splunk Phantom- How to monitor health of playbook?

Manojsai_3
New Member

Hi fellas, How can we fetch details of a playbook like action_run_id, playbook_run_id and status. We need to monitor health of a playbook with those data. If anyone have any ideas please help me out.

Labels (1)
0 Karma

victor_menezes
Communicator

Hey Manoj,

You have two options:

You can use an external search configuration to stream phantom data to Splunk and get that information on phantom_action_run or phantom_app_run indexes. I particularly use this one, and I see that phantom_action_run has the info you want to see.

OR

You can query Phantom REST api directly to get that information using the endpoints action_run, app_run or playbook_run for example. (https://docs.splunk.com/Documentation/SOARonprem/5.3.3/PlatformAPI/RESTQueryData)

0 Karma
Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...