Splunk SOAR

is it possible for branch to go back to original flow in playbook

Qingguo
Engager

Hi team

I found main flow will not run after adding branch flow ,  is it known limitation ?

Screen Shot 2021-11-16 at 8.55.19 PM.png

 

thanks

Labels (1)
Tags (1)
0 Karma
1 Solution

phanTom
SplunkTrust
SplunkTrust

@Qingguo have you checked the join on the block with 2 entry points?

If you select the "Add tag to container" block (in edit mode) and in the left-hand side select Settings > Advanced you may see one or more boxes with ticks in. This means that the block is waiting for something to run/complete and it's likely that if it goes on the `condition1` path its expecting the "set tag for instance retry" to have run but if that path isn't taken then it will never run. 

Anytime you add more than 1 line to a block, phantom will automatically add the joins for all connected actions upstream. 

Hope this helps? Mark as solution if so 😛 

 

View solution in original post

0 Karma

phanTom
SplunkTrust
SplunkTrust

@Qingguo have you checked the join on the block with 2 entry points?

If you select the "Add tag to container" block (in edit mode) and in the left-hand side select Settings > Advanced you may see one or more boxes with ticks in. This means that the block is waiting for something to run/complete and it's likely that if it goes on the `condition1` path its expecting the "set tag for instance retry" to have run but if that path isn't taken then it will never run. 

Anytime you add more than 1 line to a block, phantom will automatically add the joins for all connected actions upstream. 

Hope this helps? Mark as solution if so 😛 

 

0 Karma
Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...