IBM Security QRadar SOAR

 View Only
  • 1.  IBM SOAR PLaybook Issue

    Posted Wed March 29, 2023 01:11 AM

    Hi all! I am facing an issue while running SOAR playbook. 

    When I run the playbook manually, it does not run beyond one of the wait points in the playbook. 

    Appreciate your help.

    Thanks!



    ------------------------------
    Dushan Dissanayake Information Security Engineer
    ------------------------------


  • 2.  RE: IBM SOAR PLaybook Issue

    Posted Thu March 30, 2023 03:27 PM

    Hi Dushan,

    Can you share some information on what is happening before and what is meant to happen after the wait point? Additionally, if there is an error message that comes up, please share that as well.



    ------------------------------
    Priya Sapra
    ------------------------------



  • 3.  RE: IBM SOAR PLaybook Issue

    Posted Fri March 31, 2023 07:17 AM

    Hi Priya,

    Thank you for the response. 

    Please refer to the screenshot below which was taken from the playbook I've mentioned. The playbook only runs till the Wait Point 2 and shows the 100% completion of the tasks. 

    This is a demo playbook created to simulate the issue.
    Appreciate your help.

    Thanks!


    ------------------------------
    Dushan Dissanayake Information Security Engineer
    ------------------------------



  • 4.  RE: IBM SOAR PLaybook Issue
    Best Answer

    Posted Mon April 03, 2023 08:42 AM
    Edited by Dushan Dissanayake Thu April 06, 2023 11:37 PM

    Hi Dushan,

    I didn't try it but I think the Wait point 2 is useless. You point waits for both branches to continue which will never happen because you have a condition before who runs only one of the two paths.
    You should remove the Wait Point 2 and link the paths directly to the following task.

    Hope I helped.



    ------------------------------
    Jonathan BULACH
    ------------------------------



  • 5.  RE: IBM SOAR PLaybook Issue

    Posted Thu April 06, 2023 11:39 PM

    Hi Jonathan,

    Yes you're correct. I tried the same and it seems the playbook can continue without the wait point 2. Thanks for the input. It was really helpful. 



    ------------------------------
    Dushan Dissanayake Information Security Engineer
    ------------------------------