<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Connectivity Issue between Splunk Phantom and Splunk Enterprise - runquery action doesn't return any data in Splunk SOAR</title>
    <link>https://community.splunk.com/t5/Splunk-SOAR/Connectivity-Issue-between-Splunk-Phantom-and-Splunk-Enterprise/m-p/492055#M329</link>
    <description>&lt;P&gt;@ansusabu  thanks for your response.&lt;/P&gt;

&lt;P&gt;I tried use stats command, but it still returns 0 events.&lt;/P&gt;</description>
    <pubDate>Thu, 21 Nov 2019 10:33:39 GMT</pubDate>
    <dc:creator>d4wc3k</dc:creator>
    <dc:date>2019-11-21T10:33:39Z</dc:date>
    <item>
      <title>Connectivity Issue between Splunk Phantom and Splunk Enterprise - runquery action doesn't return any data</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Connectivity-Issue-between-Splunk-Phantom-and-Splunk-Enterprise/m-p/492053#M327</link>
      <description>&lt;P&gt;Hello everyone&lt;/P&gt;
&lt;P&gt;I need help with using Splunk App in Phantom.&lt;BR /&gt;I am trying perform searches for Splunk in Phantom, everything seems to be configured fine, final status is success.&lt;BR /&gt;The problem is that action in most cases didn't return any events.&lt;/P&gt;
&lt;P&gt;F.G&lt;BR /&gt;I have following simple query:&lt;BR /&gt;index=&lt;EM&gt;firewall&lt;/EM&gt; earliest=-1m latest=now() sourcetype="pan:threat"&lt;BR /&gt;&lt;BR /&gt;In Splunk it returns data, but if when I wanted use Phantom to perform query it doesn't return any results.&lt;BR /&gt;There is exceptions if I will use query with '| rest ' command it will return information.&lt;/P&gt;
&lt;P&gt;Should I use run query in other way ? Or maybe it's related to current configuration?&lt;/P&gt;
&lt;P&gt;Thanks a lot for response in advance.&lt;/P&gt;
&lt;P&gt;BR.&lt;BR /&gt;Dawid&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jun 2020 17:20:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Connectivity-Issue-between-Splunk-Phantom-and-Splunk-Enterprise/m-p/492053#M327</guid>
      <dc:creator>d4wc3k</dc:creator>
      <dc:date>2020-06-07T17:20:56Z</dc:date>
    </item>
    <item>
      <title>Re: Connectivity Issue between Splunk Phantom and Splunk Enterprise - runquery action doesn't return any data</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Connectivity-Issue-between-Splunk-Phantom-and-Splunk-Enterprise/m-p/492054#M328</link>
      <description>&lt;P&gt;You can use 'stats' at the end of query to return the necessary fields you require.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2019 10:29:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Connectivity-Issue-between-Splunk-Phantom-and-Splunk-Enterprise/m-p/492054#M328</guid>
      <dc:creator>ansusabu</dc:creator>
      <dc:date>2019-11-21T10:29:09Z</dc:date>
    </item>
    <item>
      <title>Re: Connectivity Issue between Splunk Phantom and Splunk Enterprise - runquery action doesn't return any data</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Connectivity-Issue-between-Splunk-Phantom-and-Splunk-Enterprise/m-p/492055#M329</link>
      <description>&lt;P&gt;@ansusabu  thanks for your response.&lt;/P&gt;

&lt;P&gt;I tried use stats command, but it still returns 0 events.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2019 10:33:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Connectivity-Issue-between-Splunk-Phantom-and-Splunk-Enterprise/m-p/492055#M329</guid>
      <dc:creator>d4wc3k</dc:creator>
      <dc:date>2019-11-21T10:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: Connectivity Issue between Splunk Phantom and Splunk Enterprise - runquery action doesn't return any data</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Connectivity-Issue-between-Splunk-Phantom-and-Splunk-Enterprise/m-p/492056#M330</link>
      <description>&lt;P&gt;Check the json file that you are receiving after the action. And try expanding the time range&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2019 10:43:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Connectivity-Issue-between-Splunk-Phantom-and-Splunk-Enterprise/m-p/492056#M330</guid>
      <dc:creator>ansusabu</dc:creator>
      <dc:date>2019-11-21T10:43:56Z</dc:date>
    </item>
    <item>
      <title>Re: Connectivity Issue between Splunk Phantom and Splunk Enterprise - runquery action doesn't return any data</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Connectivity-Issue-between-Splunk-Phantom-and-Splunk-Enterprise/m-p/492057#M331</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/199376"&gt;@ansusabu&lt;/a&gt;&lt;BR /&gt;
JSON file doesn't contain any data, please refer top its content:&lt;BR /&gt;
[{"status": "success", "parameter": {"query": "index=&lt;EM&gt;firewall&lt;/EM&gt; earliest=-1m latest=now() sourcetype=\"pan:threat\"  |  stats count by src_ip,action", "context": {"guid": "xxxx", "artifact_id": 0, "parent_action_run": []}}, "message": "Total events: 0", "data": [], "summary": {"total_events": 0}}]&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:06:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Connectivity-Issue-between-Splunk-Phantom-and-Splunk-Enterprise/m-p/492057#M331</guid>
      <dc:creator>d4wc3k</dc:creator>
      <dc:date>2020-09-30T03:06:48Z</dc:date>
    </item>
    <item>
      <title>Re: Connectivity Issue between Splunk Phantom and Splunk Enterprise - runquery action doesn't return any data</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Connectivity-Issue-between-Splunk-Phantom-and-Splunk-Enterprise/m-p/492058#M332</link>
      <description>&lt;P&gt;The previous problem was resolved by giving username right permission to get data from indexes. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
I have for now other problem, I am trying integrate other instance of Splunk with Phantom and in this case I receive following error during query execution:&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;Query invalid 'search index=*mail&lt;/EM&gt; earliest=-1m latest=now() |stats count by internal_message_id'. Error string: 'HTTP 403 Forbidden -- insufficient permission to access this resource*&lt;/P&gt;

&lt;P&gt;Did you maybe have similar issue with accessing data from Splunk ES in Phantom?&lt;/P&gt;

&lt;P&gt;BR&lt;BR /&gt;
Dawid&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:04:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Connectivity-Issue-between-Splunk-Phantom-and-Splunk-Enterprise/m-p/492058#M332</guid>
      <dc:creator>d4wc3k</dc:creator>
      <dc:date>2020-09-30T03:04:09Z</dc:date>
    </item>
    <item>
      <title>Re: Connectivity Issue between Splunk Phantom and Splunk Enterprise - runquery action doesn't return any data</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Connectivity-Issue-between-Splunk-Phantom-and-Splunk-Enterprise/m-p/492059#M333</link>
      <description>&lt;P&gt;Here are the permissions I've got for performing actions from Phantom to Splunk:&lt;/P&gt;

&lt;P&gt;rest_properties_get&lt;BR /&gt;
run_collect&lt;BR /&gt;
run_mcollect&lt;BR /&gt;
search&lt;/P&gt;

&lt;P&gt;Hopefully this helps. We haven't had any issues with it.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:13:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Connectivity-Issue-between-Splunk-Phantom-and-Splunk-Enterprise/m-p/492059#M333</guid>
      <dc:creator>WalshyB</dc:creator>
      <dc:date>2020-09-30T03:13:28Z</dc:date>
    </item>
    <item>
      <title>Re: Connectivity Issue between Splunk Phantom and Splunk Enterprise - runquery action doesn't return any data</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Connectivity-Issue-between-Splunk-Phantom-and-Splunk-Enterprise/m-p/492060#M334</link>
      <description>&lt;P&gt;@WalshyB :&lt;BR /&gt;
Adding 'search' capability for used user in Splunk resolved problem &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
I forgot add this information here.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2019 15:50:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Connectivity-Issue-between-Splunk-Phantom-and-Splunk-Enterprise/m-p/492060#M334</guid>
      <dc:creator>d4wc3k</dc:creator>
      <dc:date>2019-12-03T15:50:49Z</dc:date>
    </item>
    <item>
      <title>Re: Connectivity Issue between Splunk Phantom and Splunk Enterprise - runquery action doesn't return any data</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Connectivity-Issue-between-Splunk-Phantom-and-Splunk-Enterprise/m-p/522172#M489</link>
      <description>&lt;P&gt;Try using 'fields + *'&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 06:50:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Connectivity-Issue-between-Splunk-Phantom-and-Splunk-Enterprise/m-p/522172#M489</guid>
      <dc:creator>ansusabu</dc:creator>
      <dc:date>2020-09-30T06:50:55Z</dc:date>
    </item>
  </channel>
</rss>

