<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Installing Splunk Phantom on CentOS 7.6. RPM file in installation guide is invalid in Splunk SOAR</title>
    <link>https://community.splunk.com/t5/Splunk-SOAR/Installing-Splunk-Phantom-on-CentOS-7-6-RPM-file-in-installation/m-p/437740#M128</link>
    <description>&lt;P&gt;That is good to hear that the problem is not on my end. I will reach out to Splunk and see if either I can get an older version or if they can send me a tarball. Thanks for your help!&lt;/P&gt;</description>
    <pubDate>Fri, 21 Jun 2019 17:56:36 GMT</pubDate>
    <dc:creator>mdundas</dc:creator>
    <dc:date>2019-06-21T17:56:36Z</dc:date>
    <item>
      <title>Installing Splunk Phantom on CentOS 7.6. RPM file in installation guide is invalid</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Installing-Splunk-Phantom-on-CentOS-7-6-RPM-file-in-installation/m-p/437729#M117</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;I am attempting to install Splunk Phantom 4.5 (not the Phantom App for Splunk) on a CentOS 7.6 VM on ESXi. Using the installation guide from the Phantom site, I first made sure ports 22, 80, and 443 were open, then I downloaded the necessary repositories, cleared YUM's caches, and did a yum update. &lt;BR /&gt;Then when I tried to install the .rpm file, I got an error message in the terminal saying &lt;BR /&gt;&lt;CODE&gt;"The requested URL returned error: 404 Not Found."&lt;/CODE&gt; &lt;BR /&gt;I tried pinging the address in the terminal and entering in the URL in my browser, and it still looks like this rpm Splunk provided is invalid. Is there somewhere I can download a working .rpm? This is the version I tried to use from the installation manual: &lt;A href="https://repo.phantom.us/phantom/4.5/base/7/x86_64/phantom_repo-4.5.7532-1.x86_64.rpm" target="_blank" rel="noopener"&gt;https://repo.phantom.us/phantom/4.5/base/7/x86_64/phantom_repo-4.5.7532-1.x86_64.rpm&lt;/A&gt;&lt;BR /&gt;Any help would be appreciated.&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jun 2020 17:47:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Installing-Splunk-Phantom-on-CentOS-7-6-RPM-file-in-installation/m-p/437729#M117</guid>
      <dc:creator>mdundas</dc:creator>
      <dc:date>2020-06-07T17:47:45Z</dc:date>
    </item>
    <item>
      <title>Re: Installing Splunk Phantom on CentOS 7.6. RPM file in installation guide is invalid</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Installing-Splunk-Phantom-on-CentOS-7-6-RPM-file-in-installation/m-p/437730#M118</link>
      <description>&lt;P&gt;It's possible that your DNS is not resolving the host name for the URL. Can you ping the host or do a nslookup on the host to see if you are able to resolve the hostname? &lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 15:21:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Installing-Splunk-Phantom-on-CentOS-7-6-RPM-file-in-installation/m-p/437730#M118</guid>
      <dc:creator>koocies</dc:creator>
      <dc:date>2019-06-21T15:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: Installing Splunk Phantom on CentOS 7.6. RPM file in installation guide is invalid</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Installing-Splunk-Phantom-on-CentOS-7-6-RPM-file-in-installation/m-p/437731#M119</link>
      <description>&lt;P&gt;Yes, I have tried pinging the host and doing an nslookup on both my VM and local computer. It says it is a non-existent domain. &lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 15:53:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Installing-Splunk-Phantom-on-CentOS-7-6-RPM-file-in-installation/m-p/437731#M119</guid>
      <dc:creator>mdundas</dc:creator>
      <dc:date>2019-06-21T15:53:47Z</dc:date>
    </item>
    <item>
      <title>Re: Installing Splunk Phantom on CentOS 7.6. RPM file in installation guide is invalid</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Installing-Splunk-Phantom-on-CentOS-7-6-RPM-file-in-installation/m-p/437732#M120</link>
      <description>&lt;P&gt;Could it be that I need to somehow be signed into my Splunk Phantom account when I try to download the rpm file? I am not sure how I would do this.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 15:55:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Installing-Splunk-Phantom-on-CentOS-7-6-RPM-file-in-installation/m-p/437732#M120</guid>
      <dc:creator>mdundas</dc:creator>
      <dc:date>2019-06-21T15:55:36Z</dc:date>
    </item>
    <item>
      <title>Re: Installing Splunk Phantom on CentOS 7.6. RPM file in installation guide is invalid</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Installing-Splunk-Phantom-on-CentOS-7-6-RPM-file-in-installation/m-p/437733#M121</link>
      <description>&lt;P&gt;what's the host that you are trying to nslookup on?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 16:18:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Installing-Splunk-Phantom-on-CentOS-7-6-RPM-file-in-installation/m-p/437733#M121</guid>
      <dc:creator>koocies</dc:creator>
      <dc:date>2019-06-21T16:18:38Z</dc:date>
    </item>
    <item>
      <title>Re: Installing Splunk Phantom on CentOS 7.6. RPM file in installation guide is invalid</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Installing-Splunk-Phantom-on-CentOS-7-6-RPM-file-in-installation/m-p/437734#M122</link>
      <description>&lt;P&gt;So first I tried: &lt;A href="https://repo.phantom.us/phantom/4.5/base/7/x86_64/phantom_repo-4.5.7532-1.x86_64.rpm"&gt;https://repo.phantom.us/phantom/4.5/base/7/x86_64/phantom_repo-4.5.7532-1.x86_64.rpm&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;, which is the rpm file I am trying to download.&lt;/P&gt;

&lt;P&gt;And when that didn't work, I tried just &lt;A href="https://repo.phantom.us"&gt;https://repo.phantom.us&lt;/A&gt;. That didn't work either. &lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 16:22:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Installing-Splunk-Phantom-on-CentOS-7-6-RPM-file-in-installation/m-p/437734#M122</guid>
      <dc:creator>mdundas</dc:creator>
      <dc:date>2019-06-21T16:22:42Z</dc:date>
    </item>
    <item>
      <title>Re: Installing Splunk Phantom on CentOS 7.6. RPM file in installation guide is invalid</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Installing-Splunk-Phantom-on-CentOS-7-6-RPM-file-in-installation/m-p/437735#M123</link>
      <description>&lt;P&gt;okay, so when you're testing to see if you can resolve a hostname you need to remove the "http://" part, that's not considered part of the hostname. The hostname in this case is repo.phantom.us&lt;BR /&gt;
Try "nslookup repo.phantom.us" and let me know if you get an IP back. I did it on my laptop and got a response that the host "repo.phantom.us" is IP "54.165.15.205". you should get something similar if not the same&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 16:26:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Installing-Splunk-Phantom-on-CentOS-7-6-RPM-file-in-installation/m-p/437735#M123</guid>
      <dc:creator>koocies</dc:creator>
      <dc:date>2019-06-21T16:26:36Z</dc:date>
    </item>
    <item>
      <title>Re: Installing Splunk Phantom on CentOS 7.6. RPM file in installation guide is invalid</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Installing-Splunk-Phantom-on-CentOS-7-6-RPM-file-in-installation/m-p/437736#M124</link>
      <description>&lt;P&gt;Ok thank you, yes I was able to hit repo.phantom.us and I got an IP. But I don't get anything when I do an nslookup on the whole address.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 16:32:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Installing-Splunk-Phantom-on-CentOS-7-6-RPM-file-in-installation/m-p/437736#M124</guid>
      <dc:creator>mdundas</dc:creator>
      <dc:date>2019-06-21T16:32:30Z</dc:date>
    </item>
    <item>
      <title>Re: Installing Splunk Phantom on CentOS 7.6. RPM file in installation guide is invalid</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Installing-Splunk-Phantom-on-CentOS-7-6-RPM-file-in-installation/m-p/437737#M125</link>
      <description>&lt;P&gt;you can't nslookup a URL, only the hostname "epo.phantom.us". &lt;/P&gt;

&lt;P&gt;Now if you want to test the URL, which in this case is "&lt;A href="https://repo.phantom.us/phantom/4.5/base/7/x86_64/phantom_repo-4.5.7532-1.x86_64.rpm"&gt;https://repo.phantom.us/phantom/4.5/base/7/x86_64/phantom_repo-4.5.7532-1.x86_64.rpm&lt;/A&gt;" you'll need a different tool. Right now it sounds like you can get an IP address so Splunk knowns who to call. but splunk needs to talk to that server over HTTPS. nslookup doesn't understand HTTPS or any other protocol other than DNS, which is used to retrieve an IP using a host name. If your not too familiar with DNS I would highly recommend read up on a simple introduction. it will help you in future.  &lt;/P&gt;

&lt;P&gt;Okay enough explanation, the next step is to see if we can actually talk to that server over HTTPS. Their are a number of tools that can be used to test this, but my personal favorite is nmap. see if you have nmap install using the command "nmap -V". if you get a "command not found" you'll need to install it. you can install it using this command as root "yum install nmap -y"&lt;/P&gt;

&lt;P&gt;okay, with nmap we can test ports. The protocol HTTPS run over 443 (usually). so the command "nmap -p 443 repo.phantom.us" will tell us if that port is opened. give that a try and let me know if the port state says "open".&lt;/P&gt;

&lt;P&gt;sorry for the long reply&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 16:50:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Installing-Splunk-Phantom-on-CentOS-7-6-RPM-file-in-installation/m-p/437737#M125</guid>
      <dc:creator>koocies</dc:creator>
      <dc:date>2019-06-21T16:50:04Z</dc:date>
    </item>
    <item>
      <title>Re: Installing Splunk Phantom on CentOS 7.6. RPM file in installation guide is invalid</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Installing-Splunk-Phantom-on-CentOS-7-6-RPM-file-in-installation/m-p/437738#M126</link>
      <description>&lt;P&gt;Thank you for your help. So when I did the nmap scan, I found that port 443 was open and running https as a service.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 17:09:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Installing-Splunk-Phantom-on-CentOS-7-6-RPM-file-in-installation/m-p/437738#M126</guid>
      <dc:creator>mdundas</dc:creator>
      <dc:date>2019-06-21T17:09:46Z</dc:date>
    </item>
    <item>
      <title>Re: Installing Splunk Phantom on CentOS 7.6. RPM file in installation guide is invalid</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Installing-Splunk-Phantom-on-CentOS-7-6-RPM-file-in-installation/m-p/437739#M127</link>
      <description>&lt;P&gt;okay, so so far we found that you can get an IP &amp;amp; you can connect with no problems. This is good. The problem is looking less and less like it's on your end. &lt;/P&gt;

&lt;P&gt;I just did a check on that URL using another tool "wget", with the command "wget &lt;A href="https://repo.phantom.us/phantom/4.5/base/7/x86_64/phantom_repo-4.5.7532-1.x86_64.rpm" target="_blank"&gt;https://repo.phantom.us/phantom/4.5/base/7/x86_64/phantom_repo-4.5.7532-1.x86_64.rpm&lt;/A&gt;". wget will let you download resource over HTTP &amp;amp; HTTPS and it's a great way to troubleshoot HTTP and HTTPS. I also got a 404 error, so I don't think you are alone on this. &lt;/P&gt;

&lt;P&gt;I opened that link in my browser, but I went one directory back, so I opened "&lt;A href="https://repo.phantom.us/phantom/4.5/base/7/x86_64/" target="_blank"&gt;https://repo.phantom.us/phantom/4.5/base/7/x86_64/&lt;/A&gt;". There you can see the list of RPM files available. I don't see a file listed with the name "phantom_repo-4.5.7532-1.x86_64.rpm" so that resource is indeed missing. &lt;/P&gt;

&lt;P&gt;My recommendation at this point is to open a support ticket if you can or see if you can download an older version of Phantom. if you put in a ticket make sure to inform them that you troubleshooted and you are able to connect perfectly fine. Also inform them that the URL "&lt;A href="https://repo.phantom.us/phantom/4.5/base/7/x86_64/" target="_blank"&gt;https://repo.phantom.us/phantom/4.5/base/7/x86_64/&lt;/A&gt;" shows the file is missing&lt;/P&gt;

&lt;P&gt;sorry for putting you through all this but I think it's good to check connectivity first before looking any where else. &lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:01:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Installing-Splunk-Phantom-on-CentOS-7-6-RPM-file-in-installation/m-p/437739#M127</guid>
      <dc:creator>koocies</dc:creator>
      <dc:date>2020-09-30T01:01:34Z</dc:date>
    </item>
    <item>
      <title>Re: Installing Splunk Phantom on CentOS 7.6. RPM file in installation guide is invalid</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Installing-Splunk-Phantom-on-CentOS-7-6-RPM-file-in-installation/m-p/437740#M128</link>
      <description>&lt;P&gt;That is good to hear that the problem is not on my end. I will reach out to Splunk and see if either I can get an older version or if they can send me a tarball. Thanks for your help!&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 17:56:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Installing-Splunk-Phantom-on-CentOS-7-6-RPM-file-in-installation/m-p/437740#M128</guid>
      <dc:creator>mdundas</dc:creator>
      <dc:date>2019-06-21T17:56:36Z</dc:date>
    </item>
    <item>
      <title>Re: Installing Splunk Phantom on CentOS 7.6. RPM file in installation guide is invalid</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Installing-Splunk-Phantom-on-CentOS-7-6-RPM-file-in-installation/m-p/437741#M129</link>
      <description>&lt;P&gt;good luck there&lt;/P&gt;</description>
      <pubDate>Sat, 22 Jun 2019 14:19:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Installing-Splunk-Phantom-on-CentOS-7-6-RPM-file-in-installation/m-p/437741#M129</guid>
      <dc:creator>koocies</dc:creator>
      <dc:date>2019-06-22T14:19:03Z</dc:date>
    </item>
    <item>
      <title>Re: Installing Splunk Phantom on CentOS 7.6. RPM file in installation guide is invalid</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Installing-Splunk-Phantom-on-CentOS-7-6-RPM-file-in-installation/m-p/437742#M130</link>
      <description>&lt;P&gt;They had just updated the installation manual, and the correct version was on there. I now have Phantom completely installed. Thanks again!&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2019 12:11:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Installing-Splunk-Phantom-on-CentOS-7-6-RPM-file-in-installation/m-p/437742#M130</guid>
      <dc:creator>mdundas</dc:creator>
      <dc:date>2019-06-24T12:11:28Z</dc:date>
    </item>
  </channel>
</rss>

