<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Data Ingestion into Phantom in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Data-Ingestion-into-Phantom/m-p/502588#M85625</link>
    <description>&lt;P&gt;I want to ingest data from other sources like  a firewall or an EDR solution , is there is way to directly add data sources?&lt;/P&gt;</description>
    <pubDate>Tue, 24 Mar 2020 05:55:33 GMT</pubDate>
    <dc:creator>avinash34</dc:creator>
    <dc:date>2020-03-24T05:55:33Z</dc:date>
    <item>
      <title>Data Ingestion into Phantom</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Ingestion-into-Phantom/m-p/502586#M85623</link>
      <description>&lt;P&gt;How do i ingest data into Splunk Phantom  ?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2020 17:03:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Ingestion-into-Phantom/m-p/502586#M85623</guid>
      <dc:creator>avinash34</dc:creator>
      <dc:date>2020-03-23T17:03:38Z</dc:date>
    </item>
    <item>
      <title>Re: Data Ingestion into Phantom</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Ingestion-into-Phantom/m-p/502587#M85624</link>
      <description>&lt;P&gt;Do you want to ingest data from a Splunk instance?&lt;/P&gt;

&lt;P&gt;Check out the Splunk App for Phantom:&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/3411/"&gt;https://splunkbase.splunk.com/app/3411/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Under details, you will find a link to the documentation. It includes the chapter "Event Forwarding".&lt;/P&gt;

&lt;P&gt;When you install this app, you will get new Phantom-related trigger actions like "Run Playbook in Phantom". This way, when a Splunk alert gets triggered, it will send the events to Phantom and run a specified playbook.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2020 18:20:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Ingestion-into-Phantom/m-p/502587#M85624</guid>
      <dc:creator>whrg</dc:creator>
      <dc:date>2020-03-23T18:20:19Z</dc:date>
    </item>
    <item>
      <title>Re: Data Ingestion into Phantom</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Ingestion-into-Phantom/m-p/502588#M85625</link>
      <description>&lt;P&gt;I want to ingest data from other sources like  a firewall or an EDR solution , is there is way to directly add data sources?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2020 05:55:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Ingestion-into-Phantom/m-p/502588#M85625</guid>
      <dc:creator>avinash34</dc:creator>
      <dc:date>2020-03-24T05:55:33Z</dc:date>
    </item>
    <item>
      <title>Re: Data Ingestion into Phantom</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Ingestion-into-Phantom/m-p/502589#M85626</link>
      <description>&lt;P&gt;Phantom has some EDR/firewall apps that can help in polling data from the EDR/firewall sources. If it is not present, you can use API to ingest data into phantom.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2020 06:25:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Ingestion-into-Phantom/m-p/502589#M85626</guid>
      <dc:creator>ansusabu</dc:creator>
      <dc:date>2020-03-24T06:25:09Z</dc:date>
    </item>
    <item>
      <title>Re: Data Ingestion into Phantom</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Ingestion-into-Phantom/m-p/502590#M85627</link>
      <description>&lt;P&gt;To add on to this, any App in phantom that has as "on-poll" action can be configured for data ingestion on the associated type. &lt;/P&gt;

&lt;P&gt;We also allow you to write your own apps if they aren't available out of the box. &lt;BR /&gt;
see:&lt;BR /&gt;
&lt;A href="https://github.com/phantomcyber/phantom-apps/"&gt;https://github.com/phantomcyber/phantom-apps/&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Phantom/4.8/DevelopApps/Overview"&gt;https://docs.splunk.com/Documentation/Phantom/4.8/DevelopApps/Overview&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Mar 2020 22:18:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Ingestion-into-Phantom/m-p/502590#M85627</guid>
      <dc:creator>sam_splunk</dc:creator>
      <dc:date>2020-03-25T22:18:04Z</dc:date>
    </item>
  </channel>
</rss>

