Create a Modern Automation Broker Group
how to create a group of modern ABs
If you are not the Splunk SOAR Administrator, work with the Splunk SOAR Administrator to complete these steps.
Create one or more modern Automation Brokers before completing this task. For details, see Create a Modern Splunk SOAR Automation Broker . You cannot add Classic Automation Brokers to groups.
After you create a group, you can modify the apps, assets, and brokers associated with it.
Create an Automation Broker Group
To create a modern Automation Broker Group, follow these steps:
-
Within Splunk SOAR, from the Home menu, select Administration, then Product Settings, then Automation Broker (Modern).
-
Select +Group.
-
Enter a unique name for the new Automation Broker group.
-
Assign apps and assets to this group. Any broker that is a member of this group can work with any of the assigned apps and assets.
Note: Apps and assets must already be configured in Splunk SOAR. For details, see the appropriate documentation for your deployment type: Add and configure apps and assets to provide actions in Splunk SOAR (Cloud) or Add and configure apps and assets to provide actions in Splunk SOAR (On-premises), depending on your deployment type.-
Select an app from the available list and select a corresponding asset.
Select the external link icon next to the apps and assets selectors to open a new instance of Splunk SOAR in a separate browser window, so you can work with your system's apps and assets.
-
To add more apps and assets, select +Asset.
Note:Each asset can only be assigned to one group or standalone broker. If you specify an asset that is already assigned elsewhere, that asset is reassigned to the new group.
Assigned assets for a group are active when at least one broker in the group is active.
-
-
Add modern Automation Brokers by selecting them from the available list. If no brokers are available, make sure that they appear in the list of Modern Automation Brokers on the main Automation Broker page.
-
To save the assignments, select Save.
Automation Broker Group status
Status of the group refers to the group's high availability status and is based on how many brokers in the group are active. The count shows the number of active brokers in the group over the total number of brokers in the group.
There are three status levels.
-
Active (green indicator): Requires at least 2 active brokers, and all brokers are active.
-
Partially active (yellow indicator): Some members are active. The group can still pick up new work if at least 1 broker is active, but redundancy and capacity are degraded.
-
Inactive (red indicator): No member brokers are active.