Splunk SOAR

Filter block unable to filter on list input

N_K
Loves-to-Learn

So I've got a list containing multiple strings, depending on these strings I want to run 1 or more actions using a filter. When I use the 'in' filter to check if a certain string is in the list the matching condition is not met. 

Example

input = ['block_ioc', 'reset_password']

Filter block:

N_K_1-1726745040581.png

I can successfully use the 'in' condition in a decision block, just not a filter block. 

 

Any ideas? 

 

Labels (3)
0 Karma

marnall
Motivator

Any reason why it has to be a filter and not a decision block? Do you want it to only match on one condition and ignore the other condition?

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...