Reduce Operational Complexity with Splunk SOAR Logic Loops

Last week, we released Splunk SOAR 6.2 (Security Orchestration Automation and Response) and in the accompanying announcement blog, we highlighted some of the new key features found in this release. Today, we want to take a more in-depth look at one of those features, logic loops, and show how they make it easier than ever for security engineers and analysts to save time and cut down on repetitive manual tasks. This new iterative function allows users to automatically retry playbook actions if they fail, or continue with the rest of the playbook when an action succeeds. Logic loops can be applied to use cases like sandbox engines for malicious URL quarantine and remediation as well as forensic investigation workflows.

The following demo showcases how you can set up logic loops and some sample scenarios where you might use them.

YouTube video player

Low-Code Approach

You can configure logic loops directly in the Visual Playbook Editor with an intuitive user interface and reduce time to build playbooks. Looping functionality can be easily enabled with the simple toggle option from the Loop tab on available blocks, no coding required!

Enhance Your Playbooks

Logic Loops are available on Action, Utility and Playbook blocks for expanded use-cases. From the Loop tab on each of these block types, users can configure the following settings:

Users can also quickly and easily start debugging as needed via the loop icon in the debugger function of the Visual Playbook Editor.

Solve Multiple Security Scenarios

Logic Loops can help make investigations a breeze. Let’s say you need to run a real time response playbook on a suspicious host. Doing this process manually would require you to keep checking the host to see if the process is completed in order to get the information needed to start the next part of your response process. Loop functionality allows you to run a playbook that can continually check the host until it identifies the process has been successfully completed and then automatically kick start the next phase.

Need to start a malicious file detention workflow while using a sandbox environment? Logic Loops allow you to set up recursive action blocks that can check the sandbox at specified intervals until the desired response is triggered and then move right into the next phase of the workflow without the need for manual input.

Conclusion

We’re excited to see how users will implement logic loops into their security and automation best practices. Be sure to let us know what you think of logic loops over in the Splunk SOAR Community and if you have an idea or request for a new feature, please let us know by submitting them to Splunk Ideas. In our next look at Splunk SOAR 6.2, we’ll take a closer look at the new Panorama and FortiManager firewall apps.

Now get out there and get automating!

Related Articles

Detect Faster, Rapidly Scope an Incident, and Streamline Security Workflows with Splunk Enterprise Security 7.1
Security
5 Minute Read

Detect Faster, Rapidly Scope an Incident, and Streamline Security Workflows with Splunk Enterprise Security 7.1

Splunk Enterprise Security 7.1 offers new capabilities to help security teams detect suspicious behavior in real-time, quickly discover the scope of an incident to respond accurately, and improve security workflow efficiencies using embedded frameworks.
Fueling the SOC of the Future with Built-in Threat Research and Detections in Splunk Enterprise Security
Security
3 Minute Read

Fueling the SOC of the Future with Built-in Threat Research and Detections in Splunk Enterprise Security

The Splunk Threat Research Team develops security resources and content that helps enhance your ability to detect and respond to advanced threats.
Atlassian Confluence Vulnerability CVE-2022-26134
Security
7 Minute Read

Atlassian Confluence Vulnerability CVE-2022-26134

Get a closer look at the Atlassian Confluence Vulnerability CVE-2022-26134, including a breakdown of what happened, how to detect it, and MITRE ATT&CK mappings.