Splunk® SOAR (On-premises)

Use Splunk SOAR (On-premises)

The classic playbook editor will be deprecated in early 2025. Convert your classic playbooks to modern mode.
After the future removal of the classic playbook editor, your existing classic playbooks will continue to run, However, you will no longer be able to visualize or modify existing classic playbooks.
For details, see:

Define a workflow in a case using workbooks in

Workbooks are a template or list of standard tasks that you follow when you evaluate events or cases. Until a workbook is added to an event or case, it is only a template. When a workbook or multiple workbooks are added to an event or case, the templates are copied into, and become part of that event or case.

  • You can create workbooks to analyze events.
  • You can define a workflow in a case by adding a workbook or multiple workbooks.
  • You can combine multiple workbooks to create a more comprehensive workbook for cumulative events, cumulative cases, or cases that start out as one type of incident but end up as a different type of incident.

Your user account must have the "View Workbooks" permission to see the workbook templates. Your user account must have the "View Containers" permission to see a workbook that has been added to an event or case.

Workbooks are available from Investigation in both Summary View and Analyst View.

Add a workbook to an event or case

Perform the following steps to add a workbook to an event or case:

  1. Navigate to an event or case in .
  2. Click the Workbook tab.
  3. Click Add Workbook.
  4. Select the desired workbook from the drop-down list.
  5. Click Save.

In Analyst View in Investigate, you can click Add to add additional workbooks to the event, or click Edit to make changes to the workbook. If you edit a workbook in this manner, the changes only apply to the current event, not for all events. You must edit a workbook on the Workbooks page to make global changes. See Define tasks using workbooks in Administer .

Use workbooks to track, edit, and complete tasks

Use workbooks in a case to track, edit, and complete tasks after you have added items to the case.

Perform the following tasks to view the workbook for a case:

  1. Navigate to the case in .
  2. Click Analyst to switch to the Analyst View.
  3. Select the Workbook tab.

Add new workbooks or edit phases and tasks

You can add existing workbooks to a case, add new phases to a workbook, or manage tasks.

  1. Navigate to the case in .
  2. Click Analyst to switch to Analyst View.
  3. Select the Workbook tab.
  4. Click Add to add existing workbooks to the case.

If you have created self-contained workbooks to analyze certain types of incidents, adding multiple workbooks is useful for cases that start out like one type of incident but turn out to be a different type of incident. This helps you avoid any inconsistencies that might occur from adding individual phases or tasks during analysis. It is also possible to add individual phases or tasks.

Click Edit to add new phases or manage tasks. You can add, remove, or rename tasks, assign an owner to a task, assign authorized users, or configure whether or not a note is required for the task to be completed. If you edit a workbook in this manner, the changes only apply to the current event, not for all events. You must edit a workbook on the Workbooks page to make global changes.

Manage task details

Click on a task in the workbook column to open the task details in the main window area. You can view the task name and description supplied when the task was created.

  1. Navigate to the case in .
  2. Click Analyst to switch to Analyst view.
  3. Select the Workbook tab.
  4. Click the name of the task.
  5. Select a progress status from the drop-down list.

All tasks start with the status of Incomplete by default. As you complete tasks, additional options such as In-Progress or Complete become available. If configured to do so, some items require you to enter a note before you can mark it as complete.

A checkmark next to the task name indicates that it is complete. You can change the status of a task to Incomplete if the task requires additional information or action.

Last modified on 14 November, 2023
Add objects to a case in   Create case reports to download and share in

This documentation applies to the following versions of Splunk® SOAR (On-premises): 5.1.0, 5.2.1, 5.3.1, 5.3.2, 5.3.3, 5.3.4, 5.3.5, 5.3.6, 5.4.0, 5.5.0, 6.0.0, 6.0.1, 6.0.2, 6.1.0, 6.1.1, 6.2.0, 6.2.1, 6.2.2, 6.3.0

Was this topic useful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters