Splunk® SOAR (On-premises)

Administer Splunk SOAR (On-premises)

This documentation does not apply to the most recent version of Splunk® SOAR (On-premises). For documentation on the most recent version, go to the latest release.

View the action run history

You can view the history of actions run on your instance.

  1. From the Home menu, select Administration.
  2. Select System Health > Action Run History.

The Action Run History page displays a sortable list of action runs. Each column except for View Results is sortable. The table displays the following columns:

Column name Description
Name The name of the action that was run.
Run ID The numeric ID of the action that was run.
Event ID The numeric ID of the event the action was run against.
Start Time The time the action started.
End Time The time the action finished.
Status Whether the action succeeded or failed.
Prompted If the action taken was a prompt or manual task action, the ID of the user assigned the action appears here.
Run By The name of the user who ran the action.
View Results A hyperlink to the action results in Investigation. For prompt or manual task actions, the link opens a window containing the prompt or task results.
Last modified on 22 September, 2021
View the playbook run history in   Use ITSI to monitor the health of your deployment

This documentation applies to the following versions of Splunk® SOAR (On-premises): 5.0.1


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters