Splunk SOAR

is it possible for branch to go back to original flow in playbook

Qingguo
Engager

Hi team

I found main flow will not run after adding branch flow ,  is it known limitation ?

Screen Shot 2021-11-16 at 8.55.19 PM.png

 

thanks

Labels (1)
Tags (1)
0 Karma
1 Solution

phanTom
SplunkTrust
SplunkTrust

@Qingguo have you checked the join on the block with 2 entry points?

If you select the "Add tag to container" block (in edit mode) and in the left-hand side select Settings > Advanced you may see one or more boxes with ticks in. This means that the block is waiting for something to run/complete and it's likely that if it goes on the `condition1` path its expecting the "set tag for instance retry" to have run but if that path isn't taken then it will never run. 

Anytime you add more than 1 line to a block, phantom will automatically add the joins for all connected actions upstream. 

Hope this helps? Mark as solution if so 😛 

 

View solution in original post

0 Karma

phanTom
SplunkTrust
SplunkTrust

@Qingguo have you checked the join on the block with 2 entry points?

If you select the "Add tag to container" block (in edit mode) and in the left-hand side select Settings > Advanced you may see one or more boxes with ticks in. This means that the block is waiting for something to run/complete and it's likely that if it goes on the `condition1` path its expecting the "set tag for instance retry" to have run but if that path isn't taken then it will never run. 

Anytime you add more than 1 line to a block, phantom will automatically add the joins for all connected actions upstream. 

Hope this helps? Mark as solution if so 😛 

 

0 Karma
Get Updates on the Splunk Community!

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...

AppDynamics is now part of Splunk Ideas

Hello Splunkers, We have exciting news for you! AppDynamics has been added to the Splunk Ideas Portal. Which ...

Advanced Splunk Data Management Strategies

Join us on Wednesday, May 14, 2025, at 11 AM PDT / 2 PM EDT for an exclusive Tech Talk that delves into ...