Splunk® SOAR (Cloud)

Administer Splunk SOAR (Cloud)

The visual editor for classic playbooks is now removed. Convert your classic playbooks to modern mode. Your classic playbooks will continue to run and you can view and edit them in the SOAR Python code editor.
For details, see:

Configure how events are resolved

Set any tags needed before an event can be marked as resolved. Setting a custom field as a required tag updates the settings for the custom field.

To configure how an event is resolved, follow these steps:

  1. From the Home menu, select Administration.
  2. Select Event Settings > Resolution.
  3. Check the Require the Following Tags on Resolve checkbox.
  4. Type the names of any tags needed before an event or container can be marked as resolved. Tags can be removed by clicking the x next to the tag name.
  5. Set the action takes when artifacts are added to a resolved event. Select an action from the drop-down list that matches your business process.
    • Select Keep Event Resolved to keep events resolved when new artifacts are added.
    • Select Reopen Event to reopen any event that has a new artifact added.
    • Select Duplicate Event to create a duplicate event, and then add the new artifact to the new event.
  6. Click Save Changes.
Last modified on 20 February, 2025
Configure the response times for service level agreements   Configure labels to apply to containers

This documentation applies to the following versions of Splunk® SOAR (Cloud): current


Please expect delayed responses to documentation feedback while the team migrates content to a new system. We value your input and thank you for your patience as we work to provide you with an improved content experience!

Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters