SPLK-2003 · Question #119
When assigning an input parameter to an action while building a playbook, a user notices the artifact value they are looking for does not appear in the auto-populated list. How is it possible to…
The correct answer is A. Type the CEF datapath in manually. When building a playbook in Splunk SOAR, if the desired artifact value does not appear in the auto-populated list of input parameters for an action, users have the option to manually enter the Common Event Format (CEF) datapath for that value. This allows for greater…
Question
When assigning an input parameter to an action while building a playbook, a user notices the artifact value they are looking for does not appear in the auto-populated list. How is it possible to enter the unlisted artifact value?
Options
- AType the CEF datapath in manually.
- BDelete and recreate the artifact.
- CEdit the artifact to enable the List as Parameter option for the CEF value.
- DEdit the container to allow CEF parameters.
How the community answered
(40 responses)- A95% (38)
- B3% (1)
- C3% (1)
Explanation
When building a playbook in Splunk SOAR, if the desired artifact value does not appear in the auto-populated list of input parameters for an action, users have the option to manually enter the Common Event Format (CEF) datapath for that value. This allows for greater flexibility and customization in playbook design, ensuring that specific data points can be targeted even if they're not immediately visible in the interface. This manual entry of CEF datapaths allows users to directly reference the necessary data within artifacts, bypassing limitations of the auto-
Topics
Community Discussion
No community discussion yet for this question.