Splunk SOAR

Setting event status to close when playbook is triggered by case

shangxuan_shi
Explorer

I have promote multiple events into a case. From the case, I will run a playbook. 

I understand that I can use the following container automations to set the status to close.

  1. phantom.update()
  2. phantom.close()
  3. phantom.set_status()

However, these 3 playbook is only able to set the case's status to close. Is it possible to set the status of the promoted events within the case to close also? 


For example, I have the following events.

  • Event #1
  • Event #2
  • Event #3

When these 3 events are promoted to a case. And I run the playbook from this case, is it possible to set the status of this case and the 3 events to close . 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...