<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Phantom Splunk App - &amp;quot;post data&amp;quot; action API error in Splunk SOAR</title>
    <link>https://community.splunk.com/t5/Splunk-SOAR/Phantom-Splunk-App-quot-post-data-quot-action-API-error/m-p/425387#M90</link>
    <description>&lt;P&gt;Update to this:&lt;/P&gt;

&lt;P&gt;I enabled Trace logging in Phantom (Administration &amp;gt; System Health &amp;gt; Debugging), then examined the logs in &lt;STRONG&gt;/var/log/phantom&lt;/STRONG&gt; that changed after running the playbook with the &lt;STRONG&gt;post data&lt;/STRONG&gt; action.&lt;/P&gt;

&lt;P&gt;From that I found a log message in the file &lt;STRONG&gt;spawn.log&lt;/STRONG&gt; which gave the response to the POST api call. This told me that the &lt;STRONG&gt;post data&lt;/STRONG&gt; action is using the "receivers/simple" endpoint behind the scenes. The response (from the log file) indicated a 403 was being thrown ("insufficient permission to access this resource"), which appears to be an issue that can be resolved by adding a capability to a config file (see links below). &lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/7.2.6/RESTREF/RESTinput#receivers.2Fsimple"&gt;https://docs.splunk.com/Documentation/SplunkCloud/7.2.6/RESTREF/RESTinput#receivers.2Fsimple&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/338746/posting-to-a-receiver-using-rest-api-giving-insuff.html#answer-338819"&gt;https://answers.splunk.com/answers/338746/posting-to-a-receiver-using-rest-api-giving-insuff.html#answer-338819&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 14 Jun 2019 15:35:50 GMT</pubDate>
    <dc:creator>jamescannalte</dc:creator>
    <dc:date>2019-06-14T15:35:50Z</dc:date>
    <item>
      <title>Phantom Splunk App - "post data" action API error</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Phantom-Splunk-App-quot-post-data-quot-action-API-error/m-p/425386#M89</link>
      <description>&lt;P&gt;I'm attempting to use the "&lt;STRONG&gt;post data&lt;/STRONG&gt;" action of the Splunk app in Phantom.&lt;/P&gt;
&lt;P&gt;I'm fairly certain that I've correctly configured an asset for the app to use because the "Test Connectivity" button works and other actions on the Splunk app, such as "&lt;STRONG&gt;get host events&lt;/STRONG&gt;" work fine and succeed.&lt;/P&gt;
&lt;P&gt;Whenever I try to run the &lt;STRONG&gt;post data&lt;/STRONG&gt; action however, the action fails with &lt;STRONG&gt;Message: "Splunk server returned error from API call"&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Is there any way to get more detailed of an error message, i.e. what error the API call returned? Are there logs I can look at somewhere?&lt;/P&gt;
&lt;P&gt;Thanks for any help / suggestions.&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jun 2020 17:45:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Phantom-Splunk-App-quot-post-data-quot-action-API-error/m-p/425386#M89</guid>
      <dc:creator>jamescannalte</dc:creator>
      <dc:date>2020-06-07T17:45:13Z</dc:date>
    </item>
    <item>
      <title>Re: Phantom Splunk App - "post data" action API error</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Phantom-Splunk-App-quot-post-data-quot-action-API-error/m-p/425387#M90</link>
      <description>&lt;P&gt;Update to this:&lt;/P&gt;

&lt;P&gt;I enabled Trace logging in Phantom (Administration &amp;gt; System Health &amp;gt; Debugging), then examined the logs in &lt;STRONG&gt;/var/log/phantom&lt;/STRONG&gt; that changed after running the playbook with the &lt;STRONG&gt;post data&lt;/STRONG&gt; action.&lt;/P&gt;

&lt;P&gt;From that I found a log message in the file &lt;STRONG&gt;spawn.log&lt;/STRONG&gt; which gave the response to the POST api call. This told me that the &lt;STRONG&gt;post data&lt;/STRONG&gt; action is using the "receivers/simple" endpoint behind the scenes. The response (from the log file) indicated a 403 was being thrown ("insufficient permission to access this resource"), which appears to be an issue that can be resolved by adding a capability to a config file (see links below). &lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/7.2.6/RESTREF/RESTinput#receivers.2Fsimple"&gt;https://docs.splunk.com/Documentation/SplunkCloud/7.2.6/RESTREF/RESTinput#receivers.2Fsimple&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/338746/posting-to-a-receiver-using-rest-api-giving-insuff.html#answer-338819"&gt;https://answers.splunk.com/answers/338746/posting-to-a-receiver-using-rest-api-giving-insuff.html#answer-338819&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2019 15:35:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Phantom-Splunk-App-quot-post-data-quot-action-API-error/m-p/425387#M90</guid>
      <dc:creator>jamescannalte</dc:creator>
      <dc:date>2019-06-14T15:35:50Z</dc:date>
    </item>
  </channel>
</rss>

