Splunk Enterprise Security

Phantom: Multiple Playbook Prompt Options

jamolson
Path Finder

Hello again everyone,
Was wondering if anyone has been able to get Phantom Playbook Prompts to be able to nest response option.
I see that you can select a from a few different types of response options such as "Yes/No", "Message", or "Custom List" but what I would like is actually a "Message" AND a "Custom List" response option in one prompt.
I can do 2 prompts that feed back but I thought it would make more sense to have it all in one.

I am not sure it can even do it but I have been trying to nest the "type"

options = {"type": "list","choices": ["option_1","option_2",]}

to some thing like this

options = {["type": "message"],["type": "list","choices": ["option_1","option_2",]]}

But I cant seem to get phantom to accept it, so I am not sure if it's my syntax or if Phantom just cannot do this.
Has anyone tried?
Thank you

0 Karma

jamolson
Path Finder

Looks like this can be done in the UI on 4.5
We are running a version before this so looks like an upgrade will address this.

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...