Overview of cases - Splunk Documentation (2024)

Splunk® SOAR (Cloud)

Use Splunk SOAR (Cloud)

  1. Documentation
  2. Splunk® SOAR (Cloud)
  3. Use Splunk SOAR (Cloud)
  4. Overview of cases

Introduction

Get started using Splunk SOAR (Cloud)

Manage cases in Splunk SOAR (Cloud)

  • Create and investigate containers
  • Overview of cases
  • Create cases in
  • Add objects to a case in
  • Define a workflow in a case using workbooks in
  • Create case reports to download and share in

Overview of cases - Splunk Documentation (12)

  • Splunk 7x Metrics - use cases and success stories
  • How to make a quick monthly report of all triggere...
  • Changing default conversion provided by Splunk for...
  • Is there any documentation on Splunk Enterprise Se...
  • Example of activity from an expired user?
  • Example of inactive account activity detected use ...
  • Example of web uploads by a user to non-corporate ...
  • Example of a high volume email activity to non-cor...
  • How many panels are recommended in a dashboard?
  • Example of a prohibited process detected use case?

Read more...

The classic playbook editor will be deprecated soon. Convert your classic playbooks to modern mode.
After the future removal of the classic playbook editor, your existing classic playbooks will continue to run, However, you will no longer be able to visualize or modify existing classic playbooks.
For details, see:

  • Convert classic playbooks to modern playbooks
  • Deprecated Features in the Splunk SOAR 6.2.1 release notes

Containers can be promoted to cases. You can use cases to consolidate information from multiple containers.

  • Cases have phases and tasks, which are organized into workbooks to track and manage all the actions taken.
  • Tasks can have playbooks and actions associated with them, allowing you to automate these actions. Automating actions allows to be used to track policy and compliance, and to fulfill documentation requirements.

Last modified on 27 March, 2024

Create and investigate containersCreate cases in

This documentation applies to the following versions of Splunk® SOAR (Cloud): current

Download manual

Download this page

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

Overview of cases - Splunk Documentation (15)

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here »

Closing this box indicates that you accept our Cookie Policy.

Overview of cases - Splunk Documentation (2024)
Top Articles
Latest Posts
Article information

Author: Carmelo Roob

Last Updated:

Views: 6344

Rating: 4.4 / 5 (45 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Carmelo Roob

Birthday: 1995-01-09

Address: Apt. 915 481 Sipes Cliff, New Gonzalobury, CO 80176

Phone: +6773780339780

Job: Sales Executive

Hobby: Gaming, Jogging, Rugby, Video gaming, Handball, Ice skating, Web surfing

Introduction: My name is Carmelo Roob, I am a modern, handsome, delightful, comfortable, attractive, vast, good person who loves writing and wants to share my knowledge and understanding with you.