Splunk® SOAR (On-premises)

Use Splunk SOAR (On-premises)

This documentation does not apply to the most recent version of Splunk® SOAR (On-premises). For documentation on the most recent version, go to the latest release.

View and create notes in

You can create a note in when working with events, tasks, and cases. Use the Notes tab to view all of the notes, regardless of who created them.

Create a note

To create a note, follow these steps:

  1. Navigate to an event, task, or case in .
  2. Click the Notes tab.
  3. Enter a title and body text for your note.
  4. (Optional) Add an attachment by clicking the paper clip icon. You can upload a new attachment of up to 20 MB. To upload a larger attachment, first upload it using the Files tab. You can then add the larger file to the note as an existing file using the paper clip icon.
  5. (Optional) Click the image icon to add a new or existing image of up to 2 MB. Supported image file types include JPG, JPEG, PNG, GIF, BMP, and ICO. Images appear inline in the body of the note once the note is saved.
  6. Click Save.

To edit, delete, or mark a note as evidence, click the This image shows the more icon. icon. Once your note is marked as evidence, it appears in the Evidence tab.

Filtering notes

You can filter notes by doing the following:

  • In the Show field, select either Task Notes, General Notes, or Artifact Notes from the drop-down list. By default, all notes are displayed.
  • In the Sort field, sort by the Newest or Oldest notes.

Using HTML and Markdown in notes

Notes can include a limited set of HTML and Markdown.

supports most common Markdown elements. See the Markdown Reference on the commonmark website.

  • HTML tables are not supported.
  • HTML hyperlinks are not supported.
  • HTML inline images are not supported.
  • Hyperlinks in Markdown are supported.
  • Inline images in Markdown are supported.
Last modified on 25 May, 2023
View recommendations for mission experts, playbooks, and actions   Search within

This documentation applies to the following versions of Splunk® SOAR (On-premises): 5.0.1


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters