<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Phantom in Splunk SOAR</title>
    <link>https://community.splunk.com/t5/Splunk-SOAR/Splunk-Phantom/m-p/438596#M132</link>
    <description>&lt;P&gt;Utilizing a Saved Search for the Phantom App for Splunk including a " | table _time, host, source, sourcetype, Source_IP" portion at the end of the SPL query should allow you to forward events including that field.&lt;/P&gt;

&lt;P&gt;example:&lt;BR /&gt;
&lt;STRONG&gt;&lt;CODE&gt;notable&lt;/CODE&gt; search_name = “name of notable” | table orig_time, orig_source, src, dest&lt;/STRONG&gt;&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Event (Saved Search) Forwarding&lt;/LI&gt;
&lt;/UL&gt;

&lt;OL&gt;
&lt;LI&gt;On the Event Forwarding screen, select ‘New Saved Search Export’. The following configuration dialog will display. Fill this out as follows:&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/274528-picture1.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt; ## If you’ve formatted your Splunk search output with something like the ‘table’ command, you can easily display those fields by clicking the “Auto-Extract Fields” button. This will display them below and allow you to map them to their CEF counterparts. Mapping is important as it will give some fields contextual association with actions inside of Phantom.
Note: Clicking on the “Auto-Extract Fields” button more than once will duplicate the mapped fields, check for duplicates before saving.&lt;/LI&gt;
&lt;/OL&gt;</description>
    <pubDate>Wed, 30 Sep 2020 02:00:15 GMT</pubDate>
    <dc:creator>cblumer_splunk</dc:creator>
    <dc:date>2020-09-30T02:00:15Z</dc:date>
    <item>
      <title>Splunk Phantom</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Splunk-Phantom/m-p/438595#M131</link>
      <description>&lt;P&gt;Using Splunk Phantomm app and trying to export saved data model filds that are INHERITED parsed and can be forwared&lt;BR /&gt;
but EXTRACTED field can not be parsed and send to phantom. EX &lt;BR /&gt;
"_time",host,source,sourcetype,"Source_Ip"&lt;BR /&gt;
"2019-03-13T00:39:19.000+0200","192.168.0.1",Mikrotik,syslog,"128.201.66.155"&lt;/P&gt;

&lt;P&gt;Source ip is parsed in datamodel but could not parse and send thru phantom app&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:41:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Splunk-Phantom/m-p/438595#M131</guid>
      <dc:creator>borisk95</dc:creator>
      <dc:date>2020-09-29T23:41:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Phantom</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Splunk-Phantom/m-p/438596#M132</link>
      <description>&lt;P&gt;Utilizing a Saved Search for the Phantom App for Splunk including a " | table _time, host, source, sourcetype, Source_IP" portion at the end of the SPL query should allow you to forward events including that field.&lt;/P&gt;

&lt;P&gt;example:&lt;BR /&gt;
&lt;STRONG&gt;&lt;CODE&gt;notable&lt;/CODE&gt; search_name = “name of notable” | table orig_time, orig_source, src, dest&lt;/STRONG&gt;&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Event (Saved Search) Forwarding&lt;/LI&gt;
&lt;/UL&gt;

&lt;OL&gt;
&lt;LI&gt;On the Event Forwarding screen, select ‘New Saved Search Export’. The following configuration dialog will display. Fill this out as follows:&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/274528-picture1.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt; ## If you’ve formatted your Splunk search output with something like the ‘table’ command, you can easily display those fields by clicking the “Auto-Extract Fields” button. This will display them below and allow you to map them to their CEF counterparts. Mapping is important as it will give some fields contextual association with actions inside of Phantom.
Note: Clicking on the “Auto-Extract Fields” button more than once will duplicate the mapped fields, check for duplicates before saving.&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:00:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Splunk-Phantom/m-p/438596#M132</guid>
      <dc:creator>cblumer_splunk</dc:creator>
      <dc:date>2020-09-30T02:00:15Z</dc:date>
    </item>
  </channel>
</rss>

