- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk Phantom Remote Search Compatibility
mark_wymer
Path Finder
10-22-2021
08:05 AM
Hi all,
I’m just about to upgrade our Phantom / Splunk SOAR version to 5.0.1. The Version Compatibility matrix in the documentation for the Phantom Remote Search app suggests that this version isn’t supported though ( https://docs.splunk.com/Documentation/PhantomRemoteSearch/1.0.17/PhantomRemoteSearch/Abouttheapp )
I’m sure that it is compatible but could someone please confirm before I upgrade my Production Phantom platform.
Also, just an observation…. 14 indexes!!!! Would it not be more in keeping with general recommendations / strategy to have 1 index (or more for multiple Phantom instances) and have multiple sourcetypes?
many thanks,
Mark
