After the future removal of the classic playbook editor, your existing classic playbooks will continue to run, However, you will no longer be able to visualize or modify existing classic playbooks.
For details, see:
Create, sort, and filter notes in
Select the Notes tab to view all notes, regardless of who created them. You can create, sort, and filter notes in when working with events, tasks, and cases.
Create a note
To create a note, follow these steps:
- Navigate to an event, task, or case in .
- Select the Notes tab.
- Enter a title and body text for your note.
- (Optional) Select the paper clip icon ( ) to add an attachment. You can upload a new attachment of up to 20 MB. To upload a larger attachment, first upload it using the Files tab. You can then add the larger file to the note as an existing file using the paper clip icon.
- (Optional) Select the image icon ( ) to add a new or existing image of up to 2 MB. Supported image file types include JPG, JPEG, PNG, GIF, BMP, and ICO. Images appear inline in the body of the note after you save the note.
- Select Save.
To edit, delete, or mark a note as evidence, select the more icon ( ). After your note is marked as evidence, it appears in the Evidence tab.
Sort and filter notes
To filter notes by the type of note, use the drop-down list in the Show field to select Task Notes, General Notes, or Artifact Notes.
To sort notes by recency, use the drop-down list in the Sort field to select Newest or Oldest.
Using HTML and Markdown in notes
Notes can include a limited set of HTML and Markdown.
supports most common Markdown elements. For details, see "Markdown Reference" on the CommonMark website. The following table provides examples of HTML and Markdown elements and states whether or not supports it.
Element | Supported? |
---|---|
HTML table | No |
HTML hyperlink | No |
HTML inline image | No |
Markdown hyperlink | Yes |
Markdown inline image | Yes |
View recommended playbooks, actions, and mission experts for resolving an event | Search within |
This documentation applies to the following versions of Splunk® SOAR (On-premises): 5.1.0, 5.2.1, 5.3.1, 5.3.2, 5.3.3, 5.3.4, 5.3.5, 5.3.6, 5.4.0, 5.5.0, 6.0.0, 6.0.1, 6.0.2
Feedback submitted, thanks!