---
title: "Supported Actions"
canonical: "https://docs.infoblox.com/space/DeploymentGuideTDwDDIforSplunkSOAR/1688600726/Supported%20Actions"
format: markdown
---
The following actions are supported:

|  |  |
| --- | --- |
| **on poll** | Ingest data from Infoblox (DNS Security Events or IQ for TD Insights based on configuration) |
| **test connectivity** | Validate the asset configuration for connectivity using supplied configuration |
| **initiate indicator intel lookup** | Initiate an indicator investigation using Infoblox Dossier |
| **get indicator intel lookup result** | Retrieve the result of a previously initiated Dossier lookup for an indicator (IP/URL/Host/MAC/Hash) |
| **ip asset data lookup** | Look up asset data for a given IP address using IPAM address information |
| **get custom list** | Retrieve Custom Lists from Infoblox by ID, name, or filtering criteria |
| **remove custom list** | Delete a Custom List from Infoblox Cloud |
| **create network list** | Create a Network List with specified name, items, and optional description |
| **update network list** | Update metadata and CIDRs of a specified network list |
| **get network list** | Retrieve network lists and their metadata |
| **get iq for td insights assets** | Retrieve the list of associated assets for a given Insight ID |
| **remove network list** | Remove a specific network list by ID |
| **host asset data lookup** | Look up host asset data using IPAM host information to retrieve detailed host information from Infoblox |
| **dns record lookup** | Perform a DNS record query to retrieve associated IPs or domains from Infoblox DDI |
| **dhcp lease lookup** | Perform a DHCP lease query to retrieve lease information from Infoblox DDI |
| **indicator threat lookup** | Lookup threat intelligence details for an indicator using Infoblox TIDE |
| **create custom list** | Create a new custom list with specified details and items |
| **update custom list** | Update metadata of an existing custom list such as name, description, confidence level, threat level, or tags |
| **remove security policy** | Remove a specific Security Policy by Security Policy ID |
| **get security policy** | Retrieve Security Policies and their metadata |
| **create security policy** | Create a Security Policy, including its name, rules, associated network lists, DNS Forwarding Proxies (DFPs) etc |
| **update custom list items** | Insert or remove individual items (e.g., IPs, domains) in a custom list |
| **update security policy** | Update a specific Security Policy, including its name, rules, associated network lists, DNS Forwarding Proxies (DFPs) etc |
| **get iq for td insights indicators** | Retrieve a filtered list of indicators associated with a specific Insight ID from Infoblox, supporting multiple filter parameters |
| **get iq for td insights events** | Retrieve a detailed list of threat-related events for a specific Insight ID from Infoblox IQ for TD Insights |
| **get iq for td insight details** | Retrieve the full detail view for a single IQ for TD Insight, including counts, severity, top indicators/assets, threat actors, and recommendations |
| **update iq for td insight status** | Update the workflow status of a specific IQ for TD Insight, optionally recording an analyst comment describing the change |
| **execute iq for td recommendation actions** | Execute a single recommendation action on an IQ for TD Insight, referencing the recommendation by the ID returned in the 'get iq for td insight details' action |
| **undo iq for td recommendation action** | Reverse a previously executed recommendation action using the audit entry ID returned by the 'execute iq for td recommendation actions' action |