how to get splunk phantom specific artifact data using playbook
To get specific artifact data in Splunk Phantom using a playbook, follow these steps:
-
Start by creating a new playbook in Splunk Phantom.
-
Select the "Artifact" action from the available actions list, and then choose the artifact type that you want to retrieve data for.
-
In the "Inputs" section of the Artifact action, add any filters or search criteria that you want to use to narrow down the data that you're retrieving.
-
Next, add an "Output" action to the playbook and select the type of output you want to use. This could be a notification, an email, or a log message.
-
In the "Inputs" section of the Output action, add any relevant data or information that you want to include in the output message.
-
Save and run the playbook. The specific artifact data that you requested will be retrieved and displayed in the output message that you defined
原文地址: http://www.cveoy.top/t/topic/fd4Z 著作权归作者所有。请勿转载和采集!