Splunk® SOAR (On-premises)

Release Notes

Acrobat logo Download manual as PDF


The classic playbook editor will be deprecated soon. Convert your classic playbooks to modern mode.
After the future removal of the classic playbook editor, your existing classic playbooks will continue to run, However, you will no longer be able to visualize or modify existing classic playbooks.
For details, see:
This documentation does not apply to the most recent version of Splunk® SOAR (On-premises). For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Known issues for

Release 5.3.6

Date resolved Issue number Description
2023-09-21 PSAAS-14855 The migration tool for privileged to unprivileged SOAR does not retain known_hosts file.



Workaround:
If any git repos are failing to sync after an privileged to unprivileged migration, follow the steps in Set up a playbook repository using SSH from Configure a source control repository for your Splunk SOAR (On-premises) playbooks in Administer Splunk SOAR (On-premises).

These steps will add the git server to the known_hosts file of the phantom user in SOAR.

2023-07-24 PSAAS-14158 In a SOAR cluster, playbook blocks using the playbook API that are downstream from a block using the HTTP connector may fail with status 401.

Workaround:

Due to a change in how SOAR user sessions are handled, if the HTTP connector authenticates using different credentials than the playbooks' automation user, the playbook runs' session token is logged out, resulting in further API requests getting a status of 401. This affects active playbooks triggered by ingestion. There are four possible workarounds.

  1. Update the HTTP connector's asset's authentication fields to use the same automation user that is running the active playbook.
  2. Update the HTTP connector's asset's "Base Url" to point one of the nodes in the cluster instead of the load balancer.
  3. Put the actions run with the HTTP connector in a child playbook.
  4. Use the phantom.requests playbook API without specifying any authentication mechanism instead of using the HTTP connector.
2023-06-26 PSAAS-13898 Splunk SOAR's cron jobs generate output, which fills up mail boxes over time

Workaround:

Empty the Splunk SOAR user's mailbox. For example, if the Splunk SOAR user is phantom, you can empty the mailbox by running rm /var/mail/phantom

2023-4-15 PSAAS-13091 SOAR upgrade from 5.2.1 to 5.3.x will fail if a python3 app has been uninstalled
2023-04-15 PSAAS-13082 Upgrade SOAR unprivileged from version 5.3.1 to version 5.3.5. Encountered an issue 'Connection reset by peer' during ExternalServicesReachableCheck. at line 53 of external_services_reachable.py

Workaround:

Change line 53 from:except urllib.error.URLError: to except:
it will ignore any and all errors from the previous line, allowing you to move forward using the --ignore-warnings command line option.

2023-03-06 PSAAS-12531 searchindex_retry_entries.db grows unbounded, consuming all available disk space on the soar vault partition

Workaround:

This behavior generally occurs because of some issue when soar attempts to connect to the search endpoint. ultimately the solution is to resolve any issue connecting to the search endpoint. in the meantime, to reclaim disk space on the vault filesystem:

  • stop_phantom.sh
  • mv /opt/phantom/vault/searchindex_retry_entries.db /opt/phantom/vault/searchindex_retry_entries.db.SAVE
  • start_phantom.sh
  • when searchindex_retry_entries.db has been recreated the searchindex_retry_entries.db.SAVE can be removed.

This means that any events in searchindex_retry_entries.db at the time it is renamed to searchindex_retry_entries.db.OLD will not be retried and thus will not be sent to the search endpoint.

2023-02-03 PSAAS-12174 recreate_local_db.pyc fails with "FileNotFoundError: No such file or directory:
'/opt/phantom/dependencies/systemconfigs/opt/phantom/data/db/pg_hba.conf'"
2023-02-01 PSAAS-12146 Cannot find process engine_runner_py3 in the list of running processes
2023-01-09 PSAAS-11797 App actions fail due to unescaped null characters (PSAAS-10127)
2022-10-31 PSAAS-11004, PSAAS-11658 VPE: Values entered into custom function/Utility input arguments are deleted or modified



Workaround:

  1. Within the Visual Playbook Editor (VPE), populate a field in the utility block configuration panel.
  2. When complete, close the configuration panel.
  3. Re-open the configuration panel to populate another field.
  4. Repeat until you have completed all necessary fields.
2022-08-01 PSAAS-9665, PSAAS-11327 VPE: SOAR UI hangs in VPE debug and UI will go blank and need refresh
2022-11-28 PSAAS-11235 SOAR mobile feature is not FIPS compliant

Workaround:

If you require FIPS compliance, turn off the the SOAR Mobile feature in the SOAR Administration settings. From the Home menu, select Administration, then Mobile.

2022-11-23 PSAAS-11233 Cannot register mobile devices on SOAR instances running RHEL8
2022-11-18 PSAAS-11190 VPE: Block Names with Container - A block name with "container" cannot share its results in other blocks in the Visual Editor



Workaround:
Do not use the word 'container' in playbook block names.

2022-11-08 PSAAS-11121 AppUpdate should continue to work with custom apps that have invalid versions



Workaround:
Uninstall the custom apps that are causing the blockage.

  1. To identify those custom apps, run the following script
  2. phenv phantom_shell
    apps = App.objects.filter(disabled=False)
    for app in apps:
      if not app.known_versions:
        print(app)
    
    print('done looking up custom apps')
    
  3. Use the AppUpdate wizard to update known app. See Splunk SOAR Connector for a list of apps that you can upgrade with the wizard.
  4. Reinstall those custom apps.

Repeat these steps each time you want to upgrade certified apps.

2022-11-11 PSAAS-11118, PSAAS-8901 VPE 2: Adding a parameter to an action block deletes another parameter.



Workaround:

  1. Within the Visual Playbook Editor (VPE), populate a field in the action block configuration panel.
  2. When complete, close the configuration panel.
  3. Re-open the configuration panel to populate another field.
  4. Repeat until you have completed all necessary fields.
2022-10-31 PSAAS-11001 Wrong results in PB: "NOT IN" clause wrongly returns FALSE in SOAR when there is a null value in its condition
2022-10-25 PSAAS-10917 App editor: pyarrow dependency not correctly installed in 5.3.x



Workaround:
No workaround found

2022-10-03 PSAAS-10503 Decided cancels running playbooks on ALL nodes after restarting
2022-09-26 PSAAS-10454 UI error when navigating to case evidence tab caused by linked container that was removed by retention.



Workaround:
None.

2022-09-26 PSAAS-10411 ibackup stores the entire PostgreSQL database in every incremental backup.
2022-09-20 PSAAS-10287 Interval/Schedule ingestion settings cannot be changed



Workaround:
Changing an asset's ingest settings does not correctly update the UI. The setting is changed, but the UI does not show the correct state. If you change the ingest settings on an app's asset from Interval to Schedule or Off the UI continues to show the setting as Interval.
You can examine the JSON output of a REST request to determine the actual status of the asset's setting.

  1. Log in to your Splunk SOAR deployment.
  2. In a new browser tab, use this REST request.
    https://<Splunk SOAR deployment>/rest/asset?pretty=true&_special_app_info=true&page_size=0&_filter_id=<asset id>
    
    Replace <Splunk SOAR deployment> and <asset id> with the URL for your SOAR deployment and the asset id of the asset whose status you want to verify.
  3. Look for the "configuration" object and check the value of "polling".
    {...
    "configuration": {"ingest": {"interval_mins": "30", "container_label": "events", "polling": false}
    }
    
    When the value is false, polling is disabled. When the value is true, polling is enabled.
2022-09-13 PSAAS-10213 Running soar-prepare-system fails when SOAR has already been installed
2022-09-07 PSAAS-10127 Playbooks using Threat Grid or urlscan.io app hang on the detonation action



Workaround:
Upgrade the app you are using.

  1. From the Apps page, click App Updates.
  2. Upgrade the app to the appropriate version:
    • Threat Grid: upgrade to version 2.3.1 or higher
    • urlscan.io: upgrade to version 2.3.0 or higher
2022-09-07 PSAAS-10107 Status of Case is missing from Report



Workaround:
None known

2022-08-17 PSAAS-9891 Indicators are visible with labels that roles do not allow
2022-04-29 PSAAS-8776 Investigation page: Widget layout and visibility is not saved via "manage widgets"



Workaround:
none known at this time

2022-04-08 PSAAS-8541 Unreadable characters sporadically appear in UI



Workaround:
Refresh the browser to reload the page.

2021-09-30 PSAAS-5408 /rest/widget_data/top_playbooks_actions endpoint returns invalid playbook_name field with tags



Workaround:
Parse the result manually to exclude the span tags around the playbook name.

Last modified on 21 September, 2023
PREVIOUS
Welcome to 5.3.6
  NEXT
Fixed issues for

This documentation applies to the following versions of Splunk® SOAR (On-premises): 5.3.6


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters