Skip to main content
Splunk® SOAR (On-premises)

Administer Splunk SOAR (On-premises)

Splunk® SOAR (On-premises)
5.3.3
As of version 6.4.0, the visual editor for classic playbooks is no longer part of Splunk SOAR. Before upgrading, convert your classic playbooks to modern mode. Your classic playbooks will continue to run and you can view and edit them in the SOAR Python code editor.
For details, see:

Add tags to objects in Splunk SOAR (On-premises)

Add tags to objects in Splunk SOAR (On-premises) to help you perform the following tasks:

  • Search for objects in Splunk SOAR (On-premises)
  • Flag objects for other users
  • Automation and workflow operations
  • Affect the flow of playbooks

You can also require tags before a container can be closed. See Configure how events are resolved for more information.

Required user privileges to view, add, edit, or delete tags in Splunk SOAR (On-premises)

To view the Tags page, a user must have a role with the View System Settings privilege. To add, edit, or delete tags on the Tags page, a user must have a role with the Edit System Settings privilege.

Editing the tags on individual containers, artifacts, or assets requires a role with the matching Edit Containers, Edit Artifacts, or Edit Assets privileges. However, a user with the combination of View System Settings and Edit System Settings privileges can use the Tags page to delete or rename tags regardless of the object they are applied to, even without the edit privileges for those objects.

View tags in your Splunk SOAR (On-premises) instance

To view the Tags page, a user must have a role with the View System Settings privilege.

Perform the following steps to access the Tags page and view the existing tags in your Splunk SOAR (On-premises) instance:

  1. From the Home menu, select Administration.
  2. Select Administration Settings > Tags.

Add a new tag to Splunk SOAR (On-premises)

To add a new tag to Splunk SOAR (On-premises), perform the following steps:

  1. On the Tags page, click + Tag.
  2. Enter a new tag name.
  3. Click Create.

Tags can be added on individual objects by editing or creating that object in Splunk SOAR (On-premises) and typing them into the Tags field. For example, to create a new tag for a container in Splunk SOAR (On-premises), do the following:

  1. Navigate to the container.
  2. Click Event Info to expand the section.
  3. In the Tags field, enter the name of a new tag you want to associate with the container.

Edit existing Splunk SOAR (On-premises) tags

Renaming a tag affects all objects in Splunk SOAR (On-premises) currently using that tag. All containers, artifacts, or assets in Splunk SOAR (On-premises) with the existing tag name are updated to use the new tag name.

To edit an existing tag, perform the following steps:

  1. On the Tags page, click the edit icon for the tag. If the existing tag is already in use by another Splunk SOAR (On-premises) component, its usage is summarized in the Edit Tag window. Review this information and make notes of where you must update the tag in Splunk SOAR (On-premises) to keep your playbooks operational.
  2. Modify the name of the tag as desired.
  3. Click Save.

Delete a tag in Splunk SOAR (On-premises)

A tag exists in Splunk SOAR (On-premises) as long as at least one object still uses that tag. If you remove a tag from all objects or delete all those objects, the tag no longer shows on the Tags page. Deleting a tag affects all objects in Splunk SOAR (On-premises) currently using that tag. The deleted tag is removed from all containers, artifacts, or assets in Splunk SOAR (On-premises) currently using the tag.

To delete an existing tag, perform the following steps:

  1. On the Tags page, click the delete icon for the tag.
    If the existing tag is already in use by another Splunk SOAR (On-premises) component, its usage is summarized in the Delete Tag window. Review this information before you proceed.
  2. Click Delete.
Last modified on 20 May, 2022
Set the global action concurrency limit   Create custom CEF fields in Splunk SOAR (On-premises)

This documentation applies to the following versions of Splunk® SOAR (On-premises): 5.3.3, 5.3.4, 5.3.5, 5.3.6, 5.4.0, 5.5.0, 6.0.0, 6.0.1, 6.0.2, 6.1.0, 6.1.1, 6.2.0, 6.2.1, 6.2.2, 6.3.0, 6.3.1, 6.4.0


Please expect delayed responses to documentation feedback while the team migrates content to a new system. We value your input and thank you for your patience as we work to provide you with an improved content experience!

Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters