Splunk® Phantom (Legacy)

Build Playbooks with the Visual Editor

Acrobat logo Download manual as PDF


Splunk Phantom 4.10.7 is the final release of Splunk's Security Orchestration, Automation, and Response (SOAR) system to be called Splunk Phantom. All later versions are named Splunk SOAR (On-premises). For more information, see the Splunk SOAR (On-premises) documentation.
Acrobat logo Download topic as PDF

Run your Splunk Phantom playbook through the debugger

If you're having problems with your playbook and need to troubleshoot issues, run your playbook through the debugger.

To run your playbook through the debugger, the playbook must meet the following conditions:

  • The playbook must be saved. Playbooks in edit mode can't be debugged.
  • The playbook cannot be marked active.
  • The playbook must have a notable to run against. If there are dependencies on any artifacts as part of the notable, the artifacts must also be present and must not have been previously used by this same version of the playbook.

To view the debug content for a playbook, click the Playbook Debugger tab in the playbook editor.

Each line in the debug content starts with a date time stamp. Log entries show which action is running. The parameter sent and message it received are logged. The API call to on_finish represents a call to the End block. The playbook completes by logging a SUCCESS status.

Last modified on 01 May, 2020
PREVIOUS
View or edit playbook settings in Splunk Phantom
  NEXT
View or edit the Python code in Splunk Phantom playbooks

This documentation applies to the following versions of Splunk® Phantom (Legacy): 4.9, 4.10, 4.10.1, 4.10.2, 4.10.3, 4.10.4, 4.10.6, 4.10.7


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters