After the future removal of the classic playbook editor, your existing classic playbooks will continue to run, However, you will no longer be able to visualize or modify existing classic playbooks.
For details, see:
View the list of configured playbooks in
The playbooks list contains all your currently available playbooks and significant metadata about those playbooks. Use the playbooks list to sort, filter, and manage your playbooks.
To open the playbooks list, perform the following steps:
- From the Home menu, select Playbooks.
- Select the Playbooks tab if it's not already open.
- (Optional) Use the search field to find specific playbooks. Searches are case-insensitive and partial-word matches are supported. This search does not support booleans, such as AND, NOT, or OR. For additional information on finding existing playbooks, see Find existing playbooks for your apps in Build Playbooks with the Playbook Editor.
Use the buttons to reorder the playbooks on this page, configure source control, import playbooks, or create new playbooks:
To help improve Splunk SOAR (On-premises), Splunk collects playbook names, playbook descriptions, and custom-function names in telemetry, so don't include any personally identifiable or sensitive information in playbook names, playbook descriptions, and custom-function names.
Button | Description |
---|---|
Set the order to run playbooks with a status of Active.
| |
stores playbooks in Git repositories. See Configure a source code repository for your playbooks in Administer . Click this button to open the Update from Source Control dialog.
| |
Manage source control settings. See Configure a source code repository for your playbooks in Administer . | |
Import a playbook that was exported from another instance of .
| |
Open the Visual Playbook Editor to create a new playbook. See Create a new playbook in in Build Playbooks with the Playbook Editor. |
Select the vertical ellipsis (⋮) icon to toggle the display of the available columns in the playbook list. Items marked with a check mark (✓) are displayed in the playbook list. A horizontal scroll bar appears at the bottom of the playbook list, if needed.
Edit, delete, export, or copy a playbook
Click the name of a playbook to open it in the Visual Playbook Editor. For more information, see Create a new playbook in using the visual playbook editor in Build Playbooks with the Playbook Editor.
Check the checkbox next to the playbook name to select one or more playbooks. After playbooks are selected, you can perform the following actions:
Button | Action |
---|---|
Edit | Set the properties of the selected playbooks, not the playbooks themselves. Set the status, logging mode, safe mode, which labels the playbook operates on, the category, and tags by selecting the property value you want from the drop-down list. |
Delete | Delete the selected playbooks. A dialog box asks you to confirm your choice. |
Export | Download the playbook as a .tgz extension archive. You can export only one playbook at a time. |
Copy | Save the playbook to a repository that you have configured, such as Git. You can only copy one playbook at a time. |
Search within | Create Executive Summary reports and view all reports in |
This documentation applies to the following versions of Splunk® SOAR (On-premises): 6.2.0, 6.2.1, 6.2.2, 6.3.0
Feedback submitted, thanks!