Skip to content

Artifacts and Containers created by the app do not trigger active playbooks #81

@markcooke226

Description

@markcooke226

Name of the app
Splunk

Describe the bug
When configured to run a search in on_poll the containers/artifacts do not trigger active playbooks in the environment.

To Reproduce
Steps to reproduce the behavior:

  1. Install Splunk App 3.0.0 on SOAR cloud version 8.5.0.248
  2. Create a simple Active playbook with one action block (eg. add a comment)
  3. Set the playbook to Active
  4. Create a new asset for the Splunk App
  5. Configure it to run a search on poll (eg. earliest=-1h index=notable | head)
  6. Confirm that your test playbook is Active
  7. Run the poll now
  8. A new container should be created with an artifact
  9. Check the activity pane and confirm that the playbook was not started.

Expected behavior
Created artifacts should be set with run_automation=True

Screenshots
Active Playbook

Image Image

playbook is not activated
Image

Splunk SOAR Version (please complete the following information):

  • Splunk Cloud: 8.5.0.248
  • App Version : 3.0.0

Additional context
None

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions