Splunk® SOAR (On-premises)

Release Notes

Acrobat logo Download manual as PDF


The classic playbook editor will be deprecated soon. Convert your classic playbooks to modern mode.
After the future removal of the classic playbook editor, your existing classic playbooks will continue to run, However, you will no longer be able to visualize or modify existing classic playbooks.
For details, see:
This documentation does not apply to the most recent version of Splunk® SOAR (On-premises). For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Welcome to 5.1.0

As of this release, Splunk Phantom is .

If you are new to , read About in the Use manual to learn how you can use for security automation.

Begin your installation by reviewing the following documentation:

Planning to upgrade to from an earlier Splunk Phantom version?

If you plan to upgrade to this version from an earlier version of , read Prepare your deployment for upgrade in the Install and Upgrade manual.

requires incremental upgrades from earlier Splunk Phantom versions. Do not skip any required versions when upgrading .

For example, if you wish to upgrade to Splunk SOAR 5.1.0 from Splunk Phantom 4.9, you will first need to upgrade Splunk Phantom to 4.10.7, then upgrade to Splunk SOAR 5.0.1, before finally upgrading to Splunk SOAR 5.1.0.

What's new in 5.1.0

This release of includes the following enhancements.

Feature Description
New App Wizard and Editor An updated version of the App Wizard with new editing features is available in this release. The new App Wizard streamlines the app creation process and allows you to directly edit an apps' Python code in the user interface.
Apps are available on Splunkbase! You can now install apps for your instance from splunkbase! The buttons for App Updates and New Apps now connect to splunkbase.
OpenSSL upgraded to version 1.1.1 In order to keep pace with required updates to OpenSSL, has implemented OpenSSL 1.1.1 in this release.
urllib3 upgraded to version 1.26.7 urllib3 has been upgraded to version 1.26.7 to address issues with https proxies.
New workbook templates added Two new workbook templates have been added:
  • Risk Investigation
  • Risk Response

After upgrading to version 5.1.0, you can find these new templates in Home > Administration > Product Settings > Workbooks.

Last modified on 11 November, 2021
  NEXT
Known issues for

This documentation applies to the following versions of Splunk® SOAR (On-premises): 5.1.0


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters