Splunk® App for SOAR Export

Use the Splunk App for SOAR Export to Forward Events

Splunk App for SOAR Export release notes

Welcome to release 4.3.26

This release of Splunk App for SOAR Export was released on June 12, 2025.

Required for Splunk 10 compatibility

This release of Splunk App for SOAR Export is required for users planning to use Splunk Enterprise and Splunk Cloud Platform version 10 as a data source for Splunk SOAR.

Updates

This release of Splunk App for SOAR Export includes the following updates:

Feature Description
Updated libraries This version of Splunk App for SOAR Export has the following updated libraries for compatibility with Splunk 10.
  • solnlib 6.3.0
  • requests 2.32.3
Updated settings for adaptive response actions For fields mapped between the Splunk platform and SOAR, both the Splunk search field and mapped SOAR CEF field names and values are sent to SOAR by default. In the previous 3 releases, only the SOAR CEF field names were sent to SOAR. If you only want to send SOAR CEF fields, change this setting. For details, see Configurations in the Run adaptive response actions in Splunk ES to send notable events to Splunk SOAR article.

Fixed issues in this release

This version of Splunk App for SOAR Export is a compatibility release, created to be compatible with Splunk version 10.

Date resolved Issue number Description
2025-04-25 PAPP-35603 When forwarding events to SOAR field names are renamed even when their corresponding global mappings were removed

Known issues in this release

This version of Splunk App for SOAR Export has the following known issues. If there are no issues listed, there are currently no known issues in this release.

Last modified on 09 June, 2025
  About Splunk App for SOAR Export

This documentation applies to the following versions of Splunk® App for SOAR Export: 4.3.26


Please expect delayed responses to documentation feedback while the team migrates content to a new system. We value your input and thank you for your patience as we work to provide you with an improved content experience!

Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters