Splunk® Phantom (Legacy)

Build Playbooks with the Visual Editor

Acrobat logo Download manual as PDF

Splunk Phantom 4.10.7 is the final release of Splunk's Security Orchestration, Automation, and Response (SOAR) system to be called Splunk Phantom. All later versions are named Splunk SOAR (On-premises). For more information, see the Splunk SOAR (On-premises) documentation.
Acrobat logo Download topic as PDF

Use playbooks to automate analyst workflows in Splunk Phantom

Create a playbook in Splunk Phantom to automate security workflows so that analysts can spend more time performing analysis and investigation. The visual playbook editor (VPE) provides a visual platform for creating playbooks without having to write code.

To define a workflow that you want to automate, link together a series of actions that are provided by apps. An app is third-party software integrated with Splunk Phantom. For example, you can integrate MaxMind as a connector, which provides a geolocate ip action, or integrate Okta as a connector to provide actions such as set password or enable user. The actions available for use in your playbooks are determined by the apps integrated with Splunk Phantom.

After you create and save a playbook in Splunk Phantom, you can run playbooks when performing these tasks in Splunk Phantom:

  • Triaging or investigating cases as an analyst
  • Creating or adding a case to Investigation
  • Configuring playbooks to run automatically directly from the playbook editor
Last modified on 01 May, 2020
Create a new playbook in Splunk Phantom using the visual playbook editor

This documentation applies to the following versions of Splunk® Phantom (Legacy): 4.9, 4.10, 4.10.1, 4.10.2, 4.10.3, 4.10.4, 4.10.6, 4.10.7

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters