Splunk SOAR

How to retrieve the full raw object of app action?

CS_
Path Finder

Hey,

Is there a way to retrieve the raw object of an app action in phantom.collect?

So I have an app, which returns the following values:

data, message, status, parameter

And normally that works fine - I can call each of these in turn like this;

 

 

data_result = phantom.collect(container=container, datapath=["my_app_action:action_result.data"])
message_result = phantom.collect(container=container, datapath=["my_app_action:action_result.message"])

 

 

etc.

 

but how do I retrieve the full object? e.g. something like this:

 

 

all_result = phantom.collect(container=container, datapath=["my_app_action:action_result.*"])
all_result = phantom.collect(container=container, datapath=["my_app_action:*"])

 

 


Hope that makes sense.

Labels (1)
Tags (1)
0 Karma
1 Solution

CS_
Path Finder

After a bit more playing around and reading the documentation, i think I've found a way. You just call multiple datapaths at once:

 

paths = ['my_app_action:action_result.data',
'my_app_action:action_result.parameter',
'my_app_action:action_result.summary']

data_result = phantom.collect(container=container, datapath=paths)

 

This returns the values in the 3 datapaths all part of the same list item.

View solution in original post

0 Karma

CS_
Path Finder

After a bit more playing around and reading the documentation, i think I've found a way. You just call multiple datapaths at once:

 

paths = ['my_app_action:action_result.data',
'my_app_action:action_result.parameter',
'my_app_action:action_result.summary']

data_result = phantom.collect(container=container, datapath=paths)

 

This returns the values in the 3 datapaths all part of the same list item.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...