After the future removal of the classic playbook editor, your existing classic playbooks will continue to run, However, you will no longer be able to visualize or modify existing classic playbooks.
For details, see:
Determine your playbook flow in
The order in which you arrange the blocks and lines in your playbook determine the playbook flow.
Process playbook blocks serially
Serial processing means playbook blocks are performed in the order they are arranged.
In this example, the blocks perform as described:
- A
geolocate ip
is performed on a source IP address. - When the
geolocate ip
action is finished, alookup ip
performs.
Use serial processing when there must be a specific order to the operations, such as when a downstream block depends on the results from an upstream block.
Processing playbook blocks in parallel
You can also wire blocks to process in parallel, as shown in the following example.
In this case, the geolocate ip
and lookup ip
actions perform simultaneously, and either action can finish first. You can wire blocks in this manner when you have no dependencies on the completion of either block, or if there are no dependencies between the blocks themselves.
Arrange playbook blocks
Arrange, or rearrange the playbook flow by moving playbook blocks. You can arrange playbook blocks in the following ways:
- Individual blocks: Select and drag a single block and drop it in a new location.
- Multiple blocks: Hold the Command or Ctrl key and select multiple blocks. Then drag them as a group and drop them in a new location.
- All playbook blocks: Select anywhere on the canvas and drag all of the contents of a playbook to a new location on the canvas.
Automate responses with Splunk Enterprise Security playbook blocks | Repeat actions with logic loops |
This documentation applies to the following versions of Splunk® SOAR (Cloud): current
Feedback submitted, thanks!