<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Phantom Underprivileged Installation in Splunk SOAR</title>
    <link>https://community.splunk.com/t5/Splunk-SOAR/Splunk-Phantom-Underprivileged-Installation/m-p/582184#M775</link>
    <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222170"&gt;@phanTom&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot man&lt;/P&gt;&lt;P&gt;I tried a earlier install of phantom and it worked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 23 Jan 2022 20:22:08 GMT</pubDate>
    <dc:creator>zubairaizatron</dc:creator>
    <dc:date>2022-01-23T20:22:08Z</dc:date>
    <item>
      <title>Splunk Phantom Underprivileged Installation</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Splunk-Phantom-Underprivileged-Installation/m-p/581675#M767</link>
      <description>&lt;P&gt;Hi guys&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried installing Splunk Phantom as an underprivileged user as per the documentation:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/SOARonprem/5.0.1/Install/InstallUnprivileged" target="_blank"&gt;https://docs.splunk.com/Documentation/SOARonprem/5.0.1/Install/InstallUnprivileged&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Although I pretty much get through the process without problems, when I get to the last step i get warnings about storage&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zubairaizatron_0-1642605084136.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17609i1E62116DCD4E1E9E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="zubairaizatron_0-1642605084136.png" alt="zubairaizatron_0-1642605084136.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The installation does continue and then completes (i think)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zubairaizatron_1-1642605163078.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17610i14710024D93BA48E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="zubairaizatron_1-1642605163078.png" alt="zubairaizatron_1-1642605163078.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I then navigate to the ./bin directory and run the ./start_phantom.sh script but it gives me a connection to postgres error&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zubairaizatron_3-1642605326846.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17612iC762738B798C644F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="zubairaizatron_3-1642605326846.png" alt="zubairaizatron_3-1642605326846.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Postgres is installed so i dont know what the issue could be. Note this is a standalone instance of phantom&lt;/P&gt;&lt;P&gt;Has anyone experienced something similar?&lt;/P&gt;&lt;P&gt;Also I cannot access the frontend but I assume this is because phantom is not running&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jan 2022 15:18:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Splunk-Phantom-Underprivileged-Installation/m-p/581675#M767</guid>
      <dc:creator>zubairaizatron</dc:creator>
      <dc:date>2022-01-19T15:18:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Phantom Underprivileged Installation</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Splunk-Phantom-Underprivileged-Installation/m-p/581679#M768</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/56798"&gt;@zubairaizatron&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I am not sure what is going on with your install without checking some of the logs around the postgres startup.&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, the instructions you are following are if you want to use any other account than the default. 5.x is unprivileged by default and now runs under the &lt;STRONG&gt;phantom&lt;/STRONG&gt;&amp;nbsp;user rather than the &lt;STRONG&gt;root&lt;/STRONG&gt;&amp;nbsp;user as it did previously.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suspect you will have more luck simply installing the latest version on SOAR either via OVA or RPM.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;As per the 1st paragraph on the OVA install:&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SOARonprem/5.0.1/Install/InstallOVA" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/SOARonprem/5.0.1/Install/InstallOVA&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;"The virtual machine image of&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Splunk SOAR (On-premises)&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;is for an unprivileged installation, meaning the the application runs under the phantom user account, not as the root user."&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;If this is just for personal use then I would just go with the above. If it's for professional/licensed use then I would raise a support case under your customer entitlement.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jan 2022 15:27:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Splunk-Phantom-Underprivileged-Installation/m-p/581679#M768</guid>
      <dc:creator>phanTom</dc:creator>
      <dc:date>2022-01-19T15:27:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Phantom Underprivileged Installation</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Splunk-Phantom-Underprivileged-Installation/m-p/581768#M769</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much for your reply. This is for professional use however is is not an actual deployment, more of a poc and requires this kind of installation according to the needs of the customer.&lt;/P&gt;&lt;P&gt;That being said it seems the problem was the lack of a postgres "phantom" database.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zubairaizatron_0-1642629283268.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17615i08CE54FE9639AE18/image-size/medium?v=v2&amp;amp;px=400" role="button" title="zubairaizatron_0-1642629283268.png" alt="zubairaizatron_0-1642629283268.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I then created on and that got rid of that error. however now I am still getting the error for a supervisord.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zubairaizatron_2-1642629456266.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17617iF3011B4C2FA1D09C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="zubairaizatron_2-1642629456266.png" alt="zubairaizatron_2-1642629456266.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the start of the installation but then it gives this error&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zubairaizatron_3-1642629489757.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17618iABED7F52E22EAE42/image-size/medium?v=v2&amp;amp;px=400" role="button" title="zubairaizatron_3-1642629489757.png" alt="zubairaizatron_3-1642629489757.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;on the installation logs i found the following errors&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zubairaizatron_4-1642629575394.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17619i3E5140427C7CE18D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="zubairaizatron_4-1642629575394.png" alt="zubairaizatron_4-1642629575394.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;This one i assume i fixed by creating the phantom database in postgres&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zubairaizatron_5-1642629675453.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17620i5BA67F1797CC0EA5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="zubairaizatron_5-1642629675453.png" alt="zubairaizatron_5-1642629675453.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zubairaizatron_6-1642629741811.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17621i99ACBB59ACA3FBDA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="zubairaizatron_6-1642629741811.png" alt="zubairaizatron_6-1642629741811.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zubairaizatron_7-1642629779068.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17622iC59F31E0A293324A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="zubairaizatron_7-1642629779068.png" alt="zubairaizatron_7-1642629779068.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zubairaizatron_8-1642629824626.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17623iE1501679D0DA614B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="zubairaizatron_8-1642629824626.png" alt="zubairaizatron_8-1642629824626.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jan 2022 22:03:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Splunk-Phantom-Underprivileged-Installation/m-p/581768#M769</guid>
      <dc:creator>zubairaizatron</dc:creator>
      <dc:date>2022-01-19T22:03:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Phantom Underprivileged Installation</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Splunk-Phantom-Underprivileged-Installation/m-p/581853#M773</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/56798"&gt;@zubairaizatron&lt;/a&gt;&amp;nbsp;I have not had to install the unpriv install in this way before so I am afraid I am not sure what else I can offer.&amp;nbsp;&lt;/P&gt;&lt;P&gt;All of the requirements should have been installed and no additional configuration, outside of the installation instructions, should need to be performed to get the system up and running.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think you need to start again and be sure you didn't miss or misunderstand a step.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jan 2022 09:02:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Splunk-Phantom-Underprivileged-Installation/m-p/581853#M773</guid>
      <dc:creator>phanTom</dc:creator>
      <dc:date>2022-01-20T09:02:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Phantom Underprivileged Installation</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Splunk-Phantom-Underprivileged-Installation/m-p/582184#M775</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222170"&gt;@phanTom&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot man&lt;/P&gt;&lt;P&gt;I tried a earlier install of phantom and it worked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 23 Jan 2022 20:22:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Splunk-Phantom-Underprivileged-Installation/m-p/582184#M775</guid>
      <dc:creator>zubairaizatron</dc:creator>
      <dc:date>2022-01-23T20:22:08Z</dc:date>
    </item>
  </channel>
</rss>

