Splunk SOAR playbook
soar> playbook execute <name>
Executes a Splunk SOAR playbook, automating alert response (enrichment, blocking, notification).
Run it when you want automated response with Splunk SOAR (formerly Phantom): the playbook defines the automation (steps: IOC enrichment, firewall blocking, case creation, notification) and execution is triggered on the alert (or container). It's Splunk's SOAR platform: response orchestration. In the SOC, Splunk SOAR is case automation: the playbook executed on the SIEM alert (integration with Splunk ES) reduces response time — from automated detection to action.
Don't use it without the platform: Splunk SOAR requires deployment (or cloud) and applications (connectors) — infrastructure and licenses are a prerequisite. And beware: the playbook automates response — the logic (steps, conditions) must be designed and tested beforehand (untested playbooks can cause unwanted actions); the scope of automation (automatic blocking) must be defined with the team. Integration with sources (tool connectors) is the quality of the playbook.