All Apps and Add-ons

Splunk Integration with Resilient.

kasturea
Explorer

I want to integrate Splunk Enterprise 7.1.1 with IBM Resilient in order to create effective IRPs. What is the best practice to do it?

I have tried the "Resilient Integration for Splunk and Splunk ES" app but whenever I am trying to connect it says authentications failed, check Resilient org name and credentials in spite of entering the correct one.

Please let me know the best way to do it.

Thanks!

https://splunkbase.splunk.com/app/3861/

0 Karma
1 Solution

kasturea
Explorer

Thanks lakshman239 , I raised a case with Resilient and it got resolved after clearing the browser cache and minor change in Resilient org name field.

View solution in original post

0 Karma

kasturea
Explorer

Thanks lakshman239 , I raised a case with Resilient and it got resolved after clearing the browser cache and minor change in Resilient org name field.

0 Karma

kasturea
Explorer

I am getting below error:

Encountered the following error while trying to update: Error while posting to url=/servicesNS/nobody/SA-Resilient/admin/sa_resilientconfig/config

0 Karma

lakshman239
Influencer

Have you followed the steps in https://splunkbase.splunk.com/app/3861/#/details [ user guide] and perhaps raised a support case with them? The user guide is not available without an account in IBM resilient, so we cannot see troubleshooting tips.

The above seem to indicate its unable to reach the configs stored in the SA_resilient app. I also assume you have connectivity between splunk server and the IBM platform

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...