<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forwarding Data between Splunk ES and Phantom in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Forwarding-Data-between-Splunk-ES-and-Phantom/m-p/414932#M4966</link>
    <description>&lt;P&gt;There's documentation here that has pretty solid detail:&lt;BR /&gt;
&lt;A href="https://my.phantom.us/4.2/docs/admin/splunk"&gt;https://my.phantom.us/4.2/docs/admin/splunk&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;sign up for an account at phantom.us - it's free.&lt;/P&gt;

&lt;P&gt;However, the TL;DR is, in order to export data via a data model search, you need datamodels defined in your Splunk instance/search head - those datamodels will then have "objects" in them which should "un-grey out" the "select object" field. If you want a quick test, install the Splunk Common Information Model (CIM) app on your Splunk instance. Restart splunk after install and see if the dropdown is still grey'd out.&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/1621/"&gt;https://splunkbase.splunk.com/app/1621/&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 07 Jun 2019 03:45:39 GMT</pubDate>
    <dc:creator>kchamplin_splun</dc:creator>
    <dc:date>2019-06-07T03:45:39Z</dc:date>
    <item>
      <title>Forwarding Data between Splunk ES and Phantom</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Forwarding-Data-between-Splunk-ES-and-Phantom/m-p/414931#M4965</link>
      <description>&lt;P&gt;I am trying to send data from Splunk ES to Phantom&lt;/P&gt;

&lt;P&gt;Version is 7.2.6&lt;/P&gt;

&lt;P&gt;After downloading Phantom app from Splunk, within that App, in the forwarding option there are 2 selections:&lt;/P&gt;

&lt;P&gt;Under event forwarding tab--&amp;gt;&lt;/P&gt;

&lt;P&gt;New Data Model Export&lt;BR /&gt;
OR&lt;BR /&gt;
New Saved Search Export&lt;/P&gt;

&lt;P&gt;When I select 1st option (New Data Model Export) , it doesn't let me go through unless I fill up "Select Object" section&lt;BR /&gt;
This 'Select Object' is greyed out/has no drop down options&lt;/P&gt;

&lt;P&gt;What is this Select Object knob and where do I create an Object so that it becomes selectable over here? &lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 02:07:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Forwarding-Data-between-Splunk-ES-and-Phantom/m-p/414931#M4965</guid>
      <dc:creator>rupalekar</dc:creator>
      <dc:date>2019-06-07T02:07:21Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding Data between Splunk ES and Phantom</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Forwarding-Data-between-Splunk-ES-and-Phantom/m-p/414932#M4966</link>
      <description>&lt;P&gt;There's documentation here that has pretty solid detail:&lt;BR /&gt;
&lt;A href="https://my.phantom.us/4.2/docs/admin/splunk"&gt;https://my.phantom.us/4.2/docs/admin/splunk&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;sign up for an account at phantom.us - it's free.&lt;/P&gt;

&lt;P&gt;However, the TL;DR is, in order to export data via a data model search, you need datamodels defined in your Splunk instance/search head - those datamodels will then have "objects" in them which should "un-grey out" the "select object" field. If you want a quick test, install the Splunk Common Information Model (CIM) app on your Splunk instance. Restart splunk after install and see if the dropdown is still grey'd out.&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/1621/"&gt;https://splunkbase.splunk.com/app/1621/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 03:45:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Forwarding-Data-between-Splunk-ES-and-Phantom/m-p/414932#M4966</guid>
      <dc:creator>kchamplin_splun</dc:creator>
      <dc:date>2019-06-07T03:45:39Z</dc:date>
    </item>
  </channel>
</rss>

