Splunk® SOAR (On-premises)

Administer Splunk SOAR (On-premises)

The classic playbook editor will be deprecated in early 2025. Convert your classic playbooks to modern mode.
After the future removal of the classic playbook editor, your existing classic playbooks will continue to run, However, you will no longer be able to visualize or modify existing classic playbooks.
For details, see:

Add tags to objects in

Add tags to objects in to help you perform the following tasks:

  • Search for objects in
  • Flag objects for other users
  • Automation and workflow operations
  • Affect the flow of playbooks

You can also require tags before a container can be closed. See Configure how events are resolved for more information.

Required user privileges to view, add, edit, or delete tags in

To view the Tags page, a user must have a role with the View System Settings privilege. To add, edit, or delete tags on the Tags page, a user must have a role with the Edit System Settings privilege.

Editing the tags on individual containers, artifacts, or assets requires a role with the matching Edit Containers, Edit Artifacts, or Edit Assets privileges. However, a user with the combination of View System Settings and Edit System Settings privileges can use the Tags page to delete or rename tags regardless of the object they are applied to, even without the edit privileges for those objects.

View tags in your instance

To view the Tags page, a user must have a role with the View System Settings privilege.

Perform the following steps to access the Tags page and view the existing tags in your instance:

  1. From the Home menu, select Administration.
  2. Select Administration Settings > Tags.

Add a new tag to

To add a new tag to , perform the following steps:

  1. On the Tags page, click + Tag.
  2. Enter a new tag name.
  3. Click Create.

Tags can be added on individual objects by editing or creating that object in and typing them into the Tags field. For example, to create a new tag for a container in , do the following:

  1. Navigate to the container.
  2. Click Event Info to expand the section.
  3. In the Tags field, enter the name of a new tag you want to associate with the container.

Edit existing tags

Renaming a tag affects all objects in currently using that tag. All containers, artifacts, or assets in with the existing tag name are updated to use the new tag name.

To edit an existing tag, perform the following steps:

  1. On the Tags page, click the edit icon for the tag. If the existing tag is already in use by another component, its usage is summarized in the Edit Tag window. Review this information and make notes of where you must update the tag in to keep your playbooks operational.
  2. Modify the name of the tag as desired.
  3. Click Save.

Delete a tag in

A tag exists in as long as at least one object still uses that tag. If you remove a tag from all objects or delete all those objects, the tag no longer shows on the Tags page. Deleting a tag affects all objects in currently using that tag. The deleted tag is removed from all containers, artifacts, or assets in currently using the tag.

To delete an existing tag, perform the following steps:

  1. On the Tags page, click the delete icon for the tag.
    If the existing tag is already in use by another component, its usage is summarized in the Delete Tag window. Review this information before you proceed.
  2. Click Delete.
Last modified on 20 May, 2022
Set the global action concurrency limit   Create custom CEF fields in

This documentation applies to the following versions of Splunk® SOAR (On-premises): 5.3.3, 5.3.4, 5.3.5, 5.3.6, 5.4.0, 5.5.0, 6.0.0, 6.0.1, 6.0.2, 6.1.0, 6.1.1, 6.2.0, 6.2.1, 6.2.2, 6.3.0, 6.3.1


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters