<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Error phantom_forward:129 Splunk_home\etc\apps\phantom\bin\scripts\phantom_forward.py called without a session token. in Splunk SOAR</title>
    <link>https://community.splunk.com/t5/Splunk-SOAR/Error-phantom-forward-129-Splunk-home-etc-apps-phantom-bin/m-p/532434#M519</link>
    <description>&lt;P&gt;My the Phantom app's phantom_forwarding.log generated such logs: phantom_forward:129 - C:\Program Files\Splunk\etc\apps\phantom\bin\scripts\phantom_forward.py called without a session token.&lt;/P&gt;&lt;P&gt;Describe my current situation：&lt;/P&gt;&lt;P&gt;I am able to send events to Phantom with a saved search using the Phantom add-on. However, to send events to Phantom, I have to manually press the "Send to Phantom" button, phantom can receive the event. But the Phantom add-on can't&amp;nbsp; a&lt;SPAN class="lia-message-read"&gt;utomatically forward events to phantom,&amp;nbsp; error logs appear in the phantom_forwarding.log.&amp;nbsp;How to solve the error in the phantom_forwarding.log？&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 09 Dec 2020 08:44:28 GMT</pubDate>
    <dc:creator>chaixl</dc:creator>
    <dc:date>2020-12-09T08:44:28Z</dc:date>
    <item>
      <title>Error phantom_forward:129 Splunk_home\etc\apps\phantom\bin\scripts\phantom_forward.py called without a session token.</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Error-phantom-forward-129-Splunk-home-etc-apps-phantom-bin/m-p/532434#M519</link>
      <description>&lt;P&gt;My the Phantom app's phantom_forwarding.log generated such logs: phantom_forward:129 - C:\Program Files\Splunk\etc\apps\phantom\bin\scripts\phantom_forward.py called without a session token.&lt;/P&gt;&lt;P&gt;Describe my current situation：&lt;/P&gt;&lt;P&gt;I am able to send events to Phantom with a saved search using the Phantom add-on. However, to send events to Phantom, I have to manually press the "Send to Phantom" button, phantom can receive the event. But the Phantom add-on can't&amp;nbsp; a&lt;SPAN class="lia-message-read"&gt;utomatically forward events to phantom,&amp;nbsp; error logs appear in the phantom_forwarding.log.&amp;nbsp;How to solve the error in the phantom_forwarding.log？&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 08:44:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Error-phantom-forward-129-Splunk-home-etc-apps-phantom-bin/m-p/532434#M519</guid>
      <dc:creator>chaixl</dc:creator>
      <dc:date>2020-12-09T08:44:28Z</dc:date>
    </item>
    <item>
      <title>Re: Error phantom_forward:129 Splunk_home\etc\apps\phantom\bin\scripts\phantom_forward.py called without a session token</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Error-phantom-forward-129-Splunk-home-etc-apps-phantom-bin/m-p/532488#M520</link>
      <description>&lt;P&gt;Could you provide more info of the set-up in splunk as well as the errors you're getting?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 15:28:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Error-phantom-forward-129-Splunk-home-etc-apps-phantom-bin/m-p/532488#M520</guid>
      <dc:creator>sam_splunk</dc:creator>
      <dc:date>2020-12-09T15:28:08Z</dc:date>
    </item>
    <item>
      <title>Re: Error phantom_forward:129 Splunk_home\etc\apps\phantom\bin\scripts\phantom_forward.py called without a session token</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Error-phantom-forward-129-Splunk-home-etc-apps-phantom-bin/m-p/532573#M521</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I am currently using Splunk Enterprise&amp;nbsp;8.1.0.1&amp;nbsp; and Phantom version 4.9.39220.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;The error I'm getting is the Phantom add-on for Splunk can't&amp;nbsp; a&lt;SPAN class="lia-message-read"&gt;utomatically forward events to phantom, only by manually pressing the "Send to Phantom" button,&amp;nbsp;phantom can receive one event.&amp;nbsp;I checked&amp;nbsp;phantom_forwarding.log，&amp;nbsp;Found many errors in the log,&amp;nbsp;as shown below：&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;2020-12-07 15:36:52,372 ERROR	phantom_forward:129 - C:\Program Files\Splunk\etc\apps\phantom\bin\scripts\phantom_forward.py called without a session token.&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;I tested and found&amp;nbsp;when a new event is generated for the saved search that has been forwarded in the phantom add-on configuration,&amp;nbsp;there will be an error like the one above in the&amp;nbsp;&lt;SPAN&gt;&lt;SPAN class="lia-message-read"&gt;phantom_forwarding.log&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Here is my set-up in splunk:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In Splunk Web, I have successfully configured the Phantom Server in the App, and applied the Splunk Enterprise instance IP under the "allowed ips" in Phantom.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="1607566505(1).png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12229i9F4FA34B0BB814F4/image-size/large?v=v2&amp;amp;px=999" role="button" title="1607566505(1).png" alt="1607566505(1).png" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;1607566505(1).png&lt;/span&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="1607566578(1).png" style="width: 602px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12230i8AD8D416F2BB1510/image-size/large?v=v2&amp;amp;px=999" role="button" title="1607566578(1).png" alt="1607566578(1).png" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;1607566578(1).png&lt;/span&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="1607566685(1).png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12231i96D359187C4510B9/image-size/large?v=v2&amp;amp;px=999" role="button" title="1607566685(1).png" alt="1607566685(1).png" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;1607566685(1).png&lt;/span&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1607567371(1).png" style="width: 807px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12233iDA025E3C5885462E/image-size/large?v=v2&amp;amp;px=999" role="button" title="1607567371(1).png" alt="1607567371(1).png" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;1607567371(1).png&lt;/span&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 02:33:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Error-phantom-forward-129-Splunk-home-etc-apps-phantom-bin/m-p/532573#M521</guid>
      <dc:creator>chaixl</dc:creator>
      <dc:date>2020-12-10T02:33:08Z</dc:date>
    </item>
    <item>
      <title>Re: Error phantom_forward:129 Splunk_home\etc\apps\phantom\bin\scripts\phantom_forward.py called without a session token</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Error-phantom-forward-129-Splunk-home-etc-apps-phantom-bin/m-p/538660#M566</link>
      <description>&lt;P&gt;I was having this same issue (except with Splunk running on Linux).&amp;nbsp; Version 4.0.35 of the Phantom App was released last week and added support for Splunk Enterprise 8.1.&amp;nbsp; Upgrading to the new version of the app resolved the problem for me.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://splunkbase.splunk.com/app/3411/" target="_blank"&gt;https://splunkbase.splunk.com/app/3411/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Feb 2021 17:55:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Error-phantom-forward-129-Splunk-home-etc-apps-phantom-bin/m-p/538660#M566</guid>
      <dc:creator>ryansaunders</dc:creator>
      <dc:date>2021-02-04T17:55:48Z</dc:date>
    </item>
    <item>
      <title>Re: Error phantom_forward:129 Splunk_home\etc\apps\phantom\bin\scripts\phantom_forward.py called without a session token</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Error-phantom-forward-129-Splunk-home-etc-apps-phantom-bin/m-p/538704#M570</link>
      <description>&lt;P&gt;Thanks all for your help,&lt;/P&gt;&lt;P&gt;When I upgrade version 4.0.35 of the Phantom App, the problem is solved.&lt;/P&gt;&lt;P&gt;Thanks a lot.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 02:12:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Error-phantom-forward-129-Splunk-home-etc-apps-phantom-bin/m-p/538704#M570</guid>
      <dc:creator>chaixl</dc:creator>
      <dc:date>2021-02-05T02:12:46Z</dc:date>
    </item>
  </channel>
</rss>

