Skip to content
Back to skills

Splunk Soar

ASecurity

Expert agent for Splunk SOAR (formerly Phantom). Provides deep expertise in visual playbook development, 300+ apps with 2,800+ actions, container-based incident architecture, case management, custom app development, and Splunk Enterprise Security integration. WHEN: \"Splunk SOAR\", \"Phantom\", \"Splunk playbook\", \"SOAR app\", \"Splunk SOAR container\", \"Phantom playbook\", \"Splunk automation\", \"SOAR visual editor\".

  • 4 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 24, 2026
developmentpythonrustgotestingapisecurityperformance

Works with

  • api

Security analysis

A100/100

Scanned September 24, 2026

npx -y skills add chrishuffman5/domain-expert --skill splunk-soar --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Splunk Soar?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Splunk Soar
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/chrishuffman5-splunk-soar/badge)](https://www.skillsdirectory.com/skills/chrishuffman5-splunk-soar)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: splunk-soar
description: "Expert agent for Splunk SOAR (formerly Phantom). Provides deep expertise in visual playbook development, 300+ apps with 2,800+ actions, container-based incident architecture, case management, custom app development, and Splunk Enterprise Security integration. WHEN: \"Splunk SOAR\", \"Phantom\", \"Splunk playbook\", \"SOAR app\", \"Splunk SOAR container\", \"Phantom playbook\", \"Splunk automation\", \"SOAR visual editor\"."
license: MIT
---

# Splunk SOAR

This skill covers Splunk SOAR (formerly Phantom), Cisco/Splunk's Security Orchestration, Automation, and Response platform. It has deep knowledge of:

- Visual playbook editor (drag-and-drop workflow design)
- 300+ apps with 2,800+ automated actions
- Container-based incident architecture (events, artifacts, containers)
- Case management and investigation workflows
- Custom app development (Python-based)
- Splunk Enterprise Security integration (adaptive response)
- API-driven automation
- Role-based access control and approvals
- Clustering and high availability

## How to Approach Tasks

1. **Classify** the request:
   - **Playbook development** -- Visual editor, playbook logic, Python custom functions
   - **App configuration** -- Integration setup, action testing, custom app development
   - **Incident workflow** -- Container management, artifact handling, case management
   - **Splunk ES integration** -- Adaptive response, notable event ingestion, bidirectional sync
   - **Architecture** -- Deployment, clustering, performance tuning

2. **Gather context** -- SOAR version, deployment model, Splunk ES integration status, existing apps

3. **Recommend** actionable guidance with playbook design and Python examples

## Core Expertise

### Visual Playbook Editor

Splunk SOAR's visual editor is a drag-and-drop workflow designer:

**Playbook components:**

| Block Type | Purpose | Example |
|---|---|---|
| **Start** | Entry point, triggered by event or manual | Container created, artifact added |
| **Action** | Execute an app action | VirusTotal URL scan, AD disable user |
| **Decision** | Branch logic based on conditions | If malicious, proceed to containment |
| **Filter** | Filter data for downstream processing | Only process high-severity artifacts |
| **Format** | Build formatted messages | Email body, Slack notification |
| **Custom Function** | Python code execution | Complex logic, API calls, data transformation |
| **Prompt** | Human approval or input | "Approve endpoint isolation?" |
| **API** | REST API call (no app needed) | Call any HTTP endpoint |
| **Playbook** | Call another playbook (sub-playbook) | Reusable enrichment module |
| **End** | Terminate playbook branch | Success, failure, or informational |

### Container and Artifact Model

Splunk SOAR uses a container-based data model:

```
Container (= Incident / Case)
    |
    ├── Severity (high, medium, low, informational)
    ├── Status (new, open, closed)
    ├── Owner (assigned analyst)
    ├── Label (phishing, malware, network, etc.)
    |
    ├── Artifacts (= IOCs / Evidence)
    │   ├── Artifact 1: IP address (10.0.0.50)
    │   ├── Artifact 2: Domain (malicious-site.com)
    │   ├── Artifact 3: File hash (SHA256: abc123...)
    │   └── Artifact 4: URL (https://malicious-site.com/payload)
    |
    ├── Notes (analyst observations)
    ├── Actions (automation results)
    └── Playbook runs (execution history)
```

**Key concepts:**
- **Container** -- Represents an incident or case. Created from SIEM alerts, emails, or API.
- **Artifact** -- Individual piece of evidence (IOC, user, host). Contains CEF-formatted data.
- **CEF fields** -- Artifacts use Common Event Format field names (sourceAddress, destinationAddress, fileHash, etc.)
- **Labels** -- Categorize containers for routing to appropriate playbooks
- **Automation broker** -- On-prem component for reaching internal systems from cloud SOAR

### Playbook Development Patterns

**Phishing triage playbook flow:**
```
Start (container created with label "phishing")
    |
    v
Filter: Extract URL artifacts
    |
    v
Action: url_reputation (VirusTotal)
    |
    v
Decision: Is URL malicious?
    |
    ├── Yes:
    │   ├── Action: block_url (Web Proxy)
    │   ├── Action: send_email (notify user)
    │   ├── Format: Build incident summary
    │   └── Action: create_ticket (ServiceNow)
    |
    └── No:
        ├── Action: detonate_url (Sandbox)
        ├── Decision: Is detonation suspicious?
        │   ├── Yes: (same as malicious branch)
        │   └── No: Close container as false positive
```

### Custom App Development

Apps are Python packages that define actions:

```python
# app.py - Custom integration
import phantom.app as phantom
from phantom.base_connector import BaseConnector
from phantom.action_result import ActionResult

class MyAppConnector(BaseConnector):

    def _handle_test_connectivity(self, param):
        action_result = self.add_action_result(ActionResult(dict(param)))
        # Test API connectivity
        ret_val, response = self._make_rest_call('/api/health', action_result)
        if phantom.is_fail(ret_val):
            return action_result.set_status(phantom.APP_ERROR, "Connectivity test failed")
        return action_result.set_status(phantom.APP_SUCCESS, "Connectivity test passed")

    def _handle_lookup_ip(self, param):
        action_result = self.add_action_result(ActionResult(dict(param)))
        ip = param['ip']
        ret_val, response = self._make_rest_call(f'/api/lookup/{ip}', action_result)
        if phantom.is_fail(ret_val):
            return action_result.get_status()
        action_result.add_data(response)
        return action_result.set_status(phantom.APP_SUCCESS, f"Lookup completed for {ip}")

    def handle_action(self, param):
        action_id = self.get_action_identifier()
        if action_id == 'test_connectivity':
            return self._handle_test_connectivity(param)
        elif action_id == 'lookup_ip':
            return self._handle_lookup_ip(param)
```

```json
// app.json - App metadata
{
  "appid": "custom-threat-lookup",
  "name": "Custom Threat Lookup",
  "description": "Lookup threat data from custom API",
  "type": "reputation",
  "main_module": "app.py",
  "app_version": "1.0.0",
  "product_vendor": "Internal",
  "product_name": "Threat API",
  "actions": [
    {
      "action": "lookup ip",
      "identifier": "lookup_ip",
      "description": "Lookup IP reputation",
      "type": "investigate",
      "parameters": {
        "ip": {
          "description": "IP address to lookup",
          "data_type": "string",
          "required": true,
          "contains": ["ip"]
        }
      },
      "output": [
        {"data_path": "action_result.data.*.risk_score", "data_type": "numeric"},
        {"data_path": "action_result.data.*.threat_type", "data_type": "string"}
      ]
    }
  ]
}
```

### Splunk ES Integration

Bidirectional integration between Splunk SOAR and Enterprise Security:

- **Adaptive response** -- ES correlation searches trigger SOAR playbooks via adaptive response actions
- **Notable event ingestion** -- SOAR ingests notable events as containers with artifacts
- **Bidirectional status sync** -- Status changes in SOAR update notable events in ES
- **Context enrichment** -- SOAR enrichment results written back to ES notable events
- **Custom response actions** -- Define SOAR playbooks as adaptive response actions available in ES

### Custom Functions

Python functions that run within playbooks:

```python
def custom_risk_scoring(container=None, **kwargs):
    """Calculate composite risk score from enrichment data."""
    artifacts = phantom.get_artifacts(container_id=container["id"])
    risk_score = 0
    
    for artifact in artifacts:
        cef = artifact.get("cef", {})
        # VT malicious detections
        if cef.get("vt_positives", 0) > 5:
            risk_score += 30
        # AbuseIPDB confidence
        if cef.get("abuse_confidence", 0) > 70:
            risk_score += 25
        # Internal asset criticality
        if cef.get("asset_priority") == "critical":
            risk_score += 20

    risk_level = "critical" if risk_score > 80 else "high" if risk_score > 50 else "medium" if risk_score > 25 else "low"
    
    outputs = {"risk_score": risk_score, "risk_level": risk_level}
    
    assert json.dumps(outputs)
    return outputs
```

## Common Pitfalls

1. **Action block timeouts** -- Default action timeout may be too short for slow integrations (sandboxing, detonation). Increase per-action timeout settings.
2. **Artifact data quality** -- Poor CEF mapping from SIEM leads to missing or incorrect artifacts. Validate artifact extraction in test containers.
3. **Playbook versioning** -- Changes to active playbooks affect running instances. Use playbook versioning and test before promoting.
4. **App compatibility** -- SOAR platform upgrades may break custom apps. Test apps in staging before upgrading production.
5. **Prompt timeouts** -- Human approval prompts have configurable timeouts. Set appropriate escalation for unanswered prompts.
6. **Container volume** -- High-volume SIEM alert ingestion can overwhelm SOAR. Use filters and severity-based routing to manage container creation rate.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…