Splunk SOAR

How to Read Comments in Playbooks

SOARt_of_Lost
Path Finder

With SOAR 6.1's addition of the "Run automatically when" field, it would be great to be able to run a playbook on container resolution that can read the closure comment. Bonus points if you can explain why Comment data is separate from Event data in the export while notes aren't.

Labels (2)
0 Karma
1 Solution

SOARt_of_Lost
Path Finder

You can read the comments on a container by using the the API in a code or custom function block.

 

comment_url = phantom.build_phantom_rest_url('container', container_id, 'comments')

comment_resp_json = phantom.requests.get(comment_url, verify=False).json()

if comment_resp_json.get('count', 0) > 0:
    phantom.debug(comment_resp_json)

 

You can then parse the comments to your heart's content.

View solution in original post

SOARt_of_Lost
Path Finder

You can read the comments on a container by using the the API in a code or custom function block.

 

comment_url = phantom.build_phantom_rest_url('container', container_id, 'comments')

comment_resp_json = phantom.requests.get(comment_url, verify=False).json()

if comment_resp_json.get('count', 0) > 0:
    phantom.debug(comment_resp_json)

 

You can then parse the comments to your heart's content.

Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...