<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using Splunk Phantom post data to send data from Phantom back into Splunk in Splunk SOAR</title>
    <link>https://community.splunk.com/t5/Splunk-SOAR/Using-Splunk-Phantom-post-data-to-send-data-from-Phantom-back/m-p/473524#M230</link>
    <description>&lt;P&gt;You can use format block for formatting data and that formatted data can be used to post in SPlunk&lt;/P&gt;</description>
    <pubDate>Tue, 10 Sep 2019 07:01:45 GMT</pubDate>
    <dc:creator>ansusabu</dc:creator>
    <dc:date>2019-09-10T07:01:45Z</dc:date>
    <item>
      <title>Using Splunk Phantom post data to send data from Phantom back into Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Using-Splunk-Phantom-post-data-to-send-data-from-Phantom-back/m-p/473523#M229</link>
      <description>&lt;P&gt;Hi I am new to Splunk Phantom and have so far far&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Triggered an alert in Splunk&lt;/LI&gt;
&lt;LI&gt;This send the data into Phantom&lt;/LI&gt;
&lt;LI&gt;Phantom then runs a playbook which queries some Carbon Black stuff&lt;/LI&gt;
&lt;LI&gt;I then want to send the results of this carbon black search back into Splunk&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;I can see that i can use the Splunk App in Phantom and use the postdata command.&lt;/P&gt;
&lt;P&gt;However i only seem to be able to sned back one value at a time, with no futher remarks.&lt;BR /&gt;Is it possible to send back the complete object from Phantom into Splunk as a JSON object?&lt;/P&gt;
&lt;P&gt;For example you would have the original data you sent to Phantom and then the enhancement that you have got from running the playbook against the original data.&lt;/P&gt;
&lt;P&gt;The reason is that Splunk is the front end tool, and it would be more convienient to view any results in Splunk.&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jun 2020 17:37:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Using-Splunk-Phantom-post-data-to-send-data-from-Phantom-back/m-p/473523#M229</guid>
      <dc:creator>davidwaugh</dc:creator>
      <dc:date>2020-06-07T17:37:08Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk Phantom post data to send data from Phantom back into Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Using-Splunk-Phantom-post-data-to-send-data-from-Phantom-back/m-p/473524#M230</link>
      <description>&lt;P&gt;You can use format block for formatting data and that formatted data can be used to post in SPlunk&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2019 07:01:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Using-Splunk-Phantom-post-data-to-send-data-from-Phantom-back/m-p/473524#M230</guid>
      <dc:creator>ansusabu</dc:creator>
      <dc:date>2019-09-10T07:01:45Z</dc:date>
    </item>
  </channel>
</rss>

