Manage Modern Automation Brokers

Perform additional actions on Automation Brokers

After you have created a Modern Automation Broker, you can manage it in the following ways.

View a Modern Automation Broker

To view an Automation Brokers, follow these steps:

  1. Within Splunk SOAR, from the Home menu, select Administration, then Product Settings, then Automation Broker.

  2. Select the Modern Automation Brokers tab, then select the Brokers tab.

  3. View information about each configured broker, including its name, ID, created and updated times, status, group affiliation, and asset connection.

At this point, you can choose different actions, using the Actions () menu.

Edit a Modern Automation Broker

  1. From the Actions menu, select Edit Broker.

  2. Make modifications to any or all of the parts of the Automation Broker

    • Broker name:Changing the broker name changes the name everywhere the broker appears. Be sure to use a unique name.

    • Apps and assets: Add or remove assets associated with this broker. Assigned assets for a standalone broker will be active when the broker is active. Assigned assets for a group will be active when at least one broker in the group is active.

    • Concurrency limit: This field does not apply to Modern automation brokers.

    • Groups: Add or remove this broker from existing groups.

  3. Select Save to save your changes.

Delete a Modern Automation Broker

  1. From the Actions menu, select Delete broker.

    Note: If you delete an automation broker, it is also removed from any assigned groups.
  2. Select Delete to proceed with the delete action.

View healthcheck status of a Modern Automation Broker

  1. From the Actions menu, select View healthcheck status.

    A window displays, showing the last RPC call to and last REST call from this broker.

  2. Select OK to close the window.

Rotate broker credentials for a Modern Automation Broker

Splunk SOAR automatically rotates Automation Broker credentials (formerly called broker keys) as they approach their configured maximum age (default is 180 days). If you choose, you can manually rotate the broker credentials for the Splunk SOAR Automation Broker. For example, you might want to rotate the credentials if pairing with your Splunk SOAR instance failed during installation

When you request to rotate the broker credentials, the new credentials are immediately saved and used the next time the broker reconnects to AMQP. The previous credentials remain temporarily available and are removed later by scheduled cleanup. Reconnection might occur when the broker restarts, if there is a network glitch, or when a regularly running task removes the old credentials.

  1. From the Actions menu, select Rotate broker credentials (formerly Rotate encryption keys).

  2. Confirm that you want to rotate the credentials.