Determine your playbook flow in
The order in which you arrange the blocks and lines in your playbook determine the playbook flow.
Process playbook blocks serially
Serial processing means playbook blocks are performed in the order they are arranged.
In this example, the blocks perform as described:
- A
geolocate ip
is performed on a source IP address. - When the
geolocate ip
action is finished, alookup ip
performs.
Use serial processing when there must be a specific order to the operations, such as when a downstream block depends on the results from an upstream block.
Processing playbook blocks in parallel
You can also wire blocks to process in parallel, as shown in the following example.
In this case, the geolocate ip
and lookup ip
actions perform simultaneously, and either action can finish first. You can wire blocks in this manner when you have no dependencies on the completion of either block, or if there are no dependencies between the blocks themselves.
Require user input using the Prompt block in your playbook | Save a playbook so can access it |
This documentation applies to the following versions of Splunk® SOAR (On-premises): 5.0.1
Feedback submitted, thanks!