How can I Troubleshoot playbook issue where the wrong raw log is being included in the ticket.
For example, where ticket was created for source IP 10.xx.x.xxx and destination IP 10.x.x.x- however the raw log was for source IP 10.35.41.10, and destination IP was 10.1.3.7.
I believe when you send an event to Splunk Phantom the complete results file will be forwarded to Phantom, the result may contain more than one result from same search job. This could be one of the reason.