Splunk® SOAR (On-premises)

Release Notes

As of version 6.4.0, the visual editor for classic playbooks is no longer part of Splunk SOAR. Before upgrading, convert your classic playbooks to modern mode. Your classic playbooks will continue to run and you can view and edit them in the SOAR Python code editor.
For details, see:

Fixed issues for

Release 6.4.1

Splunk SOAR version 6.4.1 includes fixes for the following issues.


Date resolved Issue number Description
2025-04-16 PSAAS-22553 VPE: Could not run classic VPE playbook after it's opened; Need to save first
2025-04-15 PSAAS-22900 Deleting the internal SystemSettings.email_asset object cascades, deleting all SystemSettings objects.
2025-04-08 PSAAS-22217 Notes editing in events reverts if you switch tabs before saving
2025-04-02 PSAAS-22171 App packaged on MacOS: App's TGZ file might contain MacOS metadata, so SOAR cannot load the app's JSON
2025-03-18 PSAAS-20435 Looping functionality does not wait during "empty parameters list was passed to phantom.act()." error
2025-03-05 PSAAS-17481 Spawn.log does not populate after disabling telemetry and restarting Spunk SOAR
2025-03-04 PSAAS-14209 Asset health marked incorrectly "failed" sometimes (SMTP, custom apps)
2025-02-03 PSAAS-21645 VPE Data Preview: Quick action menu does not produce usable data paths in real view
Last modified on 28 May, 2025
Known issues for   Compatibility with related Splunk products

This documentation applies to the following versions of Splunk® SOAR (On-premises): 6.4.1


Please expect delayed responses to documentation feedback while the team migrates content to a new system. We value your input and thank you for your patience as we work to provide you with an improved content experience!

Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters