After the future removal of the classic playbook editor, your existing classic playbooks will continue to run, However, you will no longer be able to visualize or modify existing classic playbooks.
For details, see:
Welcome to 5.2.1
As of this release, Splunk Phantom is .
If you are new to , read About in the Use manual to learn how you can use for security automation.
Begin your installation by reviewing the following documentation:
- Known issues in this release of
- How can be installed? in the Install and Upgrade manual.
- General system requirements in the Install and Upgrade manual.
Planning to upgrade to from an earlier Splunk Phantom version?
If you plan to upgrade to this version from an earlier version of , read Prepare your deployment for upgrade in the Install and Upgrade manual.
requires incremental upgrades from earlier Splunk Phantom versions. Do not skip any required versions when upgrading .
For example, if you wish to upgrade to Splunk SOAR 5.2.1 from Splunk SOAR 5.0.1, you will first need to upgrade Splunk SOAR to 5.1.0 before upgrading to Splunk SOAR 5.2.1.
What's new in 5.2.1
This release of includes the following enhancements.
Feature | Description |
---|---|
Federal Information Processing Standard (FIPS) support | New, unprivileged deployments of Splunk SOAR (On-premises) can be created in a FIPS compliant mode.
The underlying operating system kernel must be in FIPS mode. To learn more, see: |
App, asset, and playbook relationship changes | In earlier releases, apps were linked to assets or playbooks in a many-to-many relationship using a combination of product_version , product_name , and product_vendor fields. In Splunk SOAR (On-premises) 5.2.1, apps each have a unique app_id and are linked to assets or playbooks in one-to-many relationships. During an upgrade to Splunk SOAR (On-premises) 5.2.1 apps, assets, and playbooks are migrated to this new schema.
|
New UI for assigning orphaned assets. | You can now assign orphaned assets to an App from the user interface.
|
Visual Playbook Editor: The Action Block supports formatting for input fields. | In the Visual Playbook Editor you can set the "Formatted input" property on input fields, giving you most of the formatting capabilities of the Format Block.
This allows:
|
Updated System Information UI | There is an updated UI for displaying system information about your deployment. To access the new display, select Home > Administration > About.
The interface displays:
|
Update Parser app to to version 2.4.9 | Users should immediately upgrade the Parser App to version 2.4.9 from Splunkbase or the Phantom Portal. |
Test input playbooks in the Visual Playbook Editor debugger | To test an input playbook:
|
Known issues for |
This documentation applies to the following versions of Splunk® SOAR (On-premises): 5.2.1
Feedback submitted, thanks!