Splunk App allows to take many different actions:
- You can retrieve information from Energy SOAR about alerts and cases that were created.
- You can retrieve information from Energy SOAR about jobs that are being performed by analyzers.
- You can create a new alert or a case from Splunk in Energy SOAR.
- You can run analyzers from Splunk in Energy SOAR.
Configuration
An account is used to authenticate to Energy SOAR instance. You need to provide username and a valid API key. Then add Energy SOAR instance: host, port, URI.
Cases dashboard
The application integrates a preconfigured dashboard with searches allowing you to easily interface with Energy SOAR.
You can retrieve the history of cases in Energy SOAR using the action “LIST”. For each job, you can see :
- TLP: TLP of the case
- Title: Title of the case
- Tags: Tags of the case
- Severity: Severity of the case
- Tasks: Tasks of the case by status
- Observables: Number of observables for the case
- Assignee: Current assignee for the case
- Start Date: Date and time for the start of the case
- Metrics: Current metrics for the case
- Custom Fields: Current custom fields for the case
- Status: Current status for the case with detailed resolution
- ID: ID of the case
You can click on the ID to view case details directly on Energy SOAR.
You can set filters:
- Keyword: A keyword to search on
- Status: Status of the case
- Severity: Severity of the case
- Tags: Tags of the case
- Title: Title of the case
- Assignee: Assignee of the case
- Date: Creation date of the case
Create a new case
You can create a new case from Splunk using the “CREATE” action.
Alerts dashboard
The application integrates a preconfigured dashboard with searches allowing you to easily interface with Energy SOAR and alerts.
Automation Jobs dashboard
Run new tasks
You can start new analysis from Splunk using the “RUN” action.