<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Events not received in Phantom in Splunk SOAR</title>
    <link>https://community.splunk.com/t5/Splunk-SOAR/Events-not-received-in-Phantom/m-p/412274#M68</link>
    <description>&lt;P&gt;Hi @tomaszdziwok, thanks. that explains it. I am also using non-ES splunk instance.&lt;/P&gt;

&lt;P&gt;So, the only option to get events from Splunk non-ES instance to Phantom is the saved search, no option to send alerts ? &lt;/P&gt;</description>
    <pubDate>Sun, 20 Jan 2019 22:59:56 GMT</pubDate>
    <dc:creator>damode</dc:creator>
    <dc:date>2019-01-20T22:59:56Z</dc:date>
    <item>
      <title>Events not received in Phantom</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Events-not-received-in-Phantom/m-p/412272#M66</link>
      <description>&lt;P&gt;I have created an alert in Splunk that fires off once a particular type of event is detected and also configured an alert action that should supposedly send that event to Phantom via "Send to Phantom" action.&lt;/P&gt;

&lt;P&gt;However, despite the alert having firedoff multiple times, I still see no event received in Phantom. &lt;/P&gt;

&lt;P&gt;I have tried sending the alerted event through "run Playbook in Phantom" alert action as well, still of no use. I have ensured connectivity between Phantom and Splunk is successful.&lt;/P&gt;

&lt;P&gt;Tried other ways such as exporting saved search available in Splunk Phantom app, but that didnt work either. Can someone please share some documentation on the phantom app as well ? Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 04:46:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Events-not-received-in-Phantom/m-p/412272#M66</guid>
      <dc:creator>damode</dc:creator>
      <dc:date>2019-01-18T04:46:51Z</dc:date>
    </item>
    <item>
      <title>Re: Events not received in Phantom</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Events-not-received-in-Phantom/m-p/412273#M67</link>
      <description>&lt;P&gt;I had the exact same problem. In my case, I was trying to run the Phantom app on a Splunk Core instance (non-ES). As it turns out, the "Send to Phantom" alert action only works with ES Adaptive Response Framework. &lt;/P&gt;

&lt;P&gt;From the phantom app's README: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;PAPP-2914 - Alert action is available on non-ES capable Splunk instances. This feature is only supported on Splunk ES capable instances, and will be removed in future versions from display on Non-ES instances.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And this is the python code that exits with code 0 without showing the user an error:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;try:
    from cim_actions import ModularAction
except:
    sys.exit(0)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The cim_actions module is part of Adaptive Response.&lt;/P&gt;

&lt;P&gt;The only reliable documentation I have found for the app is the README itself. &lt;/P&gt;

&lt;P&gt;Exporting the saved search should have worked though. Any sign of related issues in _internal? &lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 15:21:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Events-not-received-in-Phantom/m-p/412273#M67</guid>
      <dc:creator>tomaszdziwok</dc:creator>
      <dc:date>2019-01-18T15:21:45Z</dc:date>
    </item>
    <item>
      <title>Re: Events not received in Phantom</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Events-not-received-in-Phantom/m-p/412274#M68</link>
      <description>&lt;P&gt;Hi @tomaszdziwok, thanks. that explains it. I am also using non-ES splunk instance.&lt;/P&gt;

&lt;P&gt;So, the only option to get events from Splunk non-ES instance to Phantom is the saved search, no option to send alerts ? &lt;/P&gt;</description>
      <pubDate>Sun, 20 Jan 2019 22:59:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Events-not-received-in-Phantom/m-p/412274#M68</guid>
      <dc:creator>damode</dc:creator>
      <dc:date>2019-01-20T22:59:56Z</dc:date>
    </item>
    <item>
      <title>Re: Events not received in Phantom</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Events-not-received-in-Phantom/m-p/412275#M69</link>
      <description>&lt;P&gt;I tried forwarding events using the &lt;STRONG&gt;New Saved Search Export&lt;/STRONG&gt; option&lt;BR /&gt;
, however I am getting this error - &lt;CODE&gt;File contains parsing errors: [line 2]: '\xef\xbb\xbf# Version 7.2.1\n'&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jan 2019 00:57:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Events-not-received-in-Phantom/m-p/412275#M69</guid>
      <dc:creator>damode</dc:creator>
      <dc:date>2019-01-21T00:57:02Z</dc:date>
    </item>
    <item>
      <title>Re: Events not received in Phantom</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Events-not-received-in-Phantom/m-p/412276#M70</link>
      <description>&lt;P&gt;That is strange. It looks like there is an unexpected BOM in the header of some file (I assume it's a python script). I did not experience this issue. If you identify exactly what file it is (perhaps through a stacktrace for this error in _internal), you could re-install/update that app and it would hopefully resolve the issue. &lt;/P&gt;</description>
      <pubDate>Mon, 21 Jan 2019 08:34:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Events-not-received-in-Phantom/m-p/412276#M70</guid>
      <dc:creator>tomaszdziwok</dc:creator>
      <dc:date>2019-01-21T08:34:18Z</dc:date>
    </item>
    <item>
      <title>Re: Events not received in Phantom</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Events-not-received-in-Phantom/m-p/412277#M71</link>
      <description>&lt;P&gt;I managed to get alerting to work with a hacky solution. Note; this is not officially supported, and I am not the author of the code so I cannot vouch for it. &lt;BR /&gt;
On my Splunk instance, I downloaded the file from (&lt;A href="https://github.com/secops4thewin/TA-securitytrails/blob/7faf165ea8465f2feae8035a3c3405115cc9e399/bin/ta_securitytrails/cim_actions.py" target="_blank"&gt;https://github.com/secops4thewin/TA-securitytrails/blob/7faf165ea8465f2feae8035a3c3405115cc9e399/bin/ta_securitytrails/cim_actions.py&lt;/A&gt;) and placed it in $SPLUNK_HOME/etc/apps/phantom/bin/. (the file is named cim_actions.py). With this in place, alerting is working fine for me. &lt;BR /&gt;
&lt;STRONG&gt;Disclaimer&lt;/STRONG&gt;; I would definitely not recommend running this in production. It's &lt;STRONG&gt;not a supported solution&lt;/STRONG&gt; and I certainly &lt;STRONG&gt;can't guarantee that this code is trustworthy&lt;/STRONG&gt;. If you choose to use this solution, you will be allowing &lt;STRONG&gt;the downloaded script to run with near-admin privileges on your Splunk instance!&lt;/STRONG&gt; Again, I cannot stress enough that you &lt;STRONG&gt;should not use this&lt;/STRONG&gt; without vetting the script first. That being said if, like me, you are just trying to get alerting working on an isolated dev instance; it might be worth a try. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:51:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Events-not-received-in-Phantom/m-p/412277#M71</guid>
      <dc:creator>tomaszdziwok</dc:creator>
      <dc:date>2020-09-29T22:51:10Z</dc:date>
    </item>
    <item>
      <title>Re: Events not received in Phantom</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Events-not-received-in-Phantom/m-p/412278#M72</link>
      <description>&lt;P&gt;I resolved this issue by downgrading  the app from 2.5.2.3 to 2.5.2. I was able to get events in Phantom after that.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jan 2019 22:18:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Events-not-received-in-Phantom/m-p/412278#M72</guid>
      <dc:creator>damode</dc:creator>
      <dc:date>2019-01-21T22:18:19Z</dc:date>
    </item>
    <item>
      <title>Re: Events not received in Phantom</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Events-not-received-in-Phantom/m-p/412279#M73</link>
      <description>&lt;P&gt;thanks alot for sharing this! &lt;BR /&gt;
I will definitely give that a try on my test instance.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jan 2019 22:21:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Events-not-received-in-Phantom/m-p/412279#M73</guid>
      <dc:creator>damode</dc:creator>
      <dc:date>2019-01-21T22:21:30Z</dc:date>
    </item>
    <item>
      <title>Re: Events not received in Phantom</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Events-not-received-in-Phantom/m-p/412280#M74</link>
      <description>&lt;P&gt;@damode, the non-hacky approach is to install Splunk Common Information Model (CIM) app. It should be documented as a dependency.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 16:14:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Events-not-received-in-Phantom/m-p/412280#M74</guid>
      <dc:creator>Iliasdiamantako</dc:creator>
      <dc:date>2020-03-09T16:14:58Z</dc:date>
    </item>
  </channel>
</rss>

