Getting Data In

Events Are Not Ingesting from Splunk ES To Phantom

rsantoso_splunk
Splunk Employee
Splunk Employee

Phantom version 4.1.94
Splunk version 6.6.5
Splunk Phantom App 2.5.23
ES version 4.7.1

When go to Splunk ES Notables, there also not able to see "Send to Phantom" action in "Run Adaptive Response Actions" from notables.

The ERROR messages:

15:55:02.540 -0800 INFO sendmodalert - Invoking modular alert action=sendtophantom for search="" sid="rt_scheduler_adminxyz_RMD519*xyz*_atutc_123.456" in app="SA-" owner="admin" type="saved"

15:55:02.546 -0800 ERROR sendmodalert - Error in 'sendalert' command: Alert action "sendtophantom" not found.

15:55:02.546 -0800 ERROR SearchScheduler - Error in 'sendalert' command: Alert action "sendtophantom" not found., search='sendalert sendtophantom results_file="/opt/splunk/var/run/splunk/dispatch/rt_scheduler_adminxyz_RMD*xyz*_atutc_123.456/results.csv.gz" results_link=""'

The Alert Permission:
- Splunk > Settings > Alert Actions > Send to Phantom > Permissions
- Splunk > Settings > Alert Actions > Run Playbook in Phantom > Permissions
These have permission allowed for All Apps and Everyone

0 Karma
1 Solution

rsantoso_splunk
Splunk Employee
Splunk Employee

The ES need to import custom apps (phantom) to Enterprise Security. It is believe this has not been setup.

In order to set this up, here are the steps:
1. Go to Enterprise Security > General > App Imports Update > update_es
2. On the Application Regular Expression enter the following at the end:
| (phantom)
The Application Regular Expression will be:
(appsbrowser)|(search)|([ST]A-.)|(Splunk_[ST]A_.)|(DA-ESS-.)|(Splunk_DA-ESS_.)|(phantom)
3. Save this
4. Once you save it, you need to enable the update_es.
On the right hand side of the update_es , you will see the status, click on Enable
5. Now try to again with you Correlation Search, you will find phantom will be in the list of your Adaptive Response Action.
6. Once this is done you can create the Saved search, click on Save and Preview.

For further information on ES App Imports Update:
https://docs.splunk.com/Documentation/ES/4.7.1/Install/ImportCustomApps

View solution in original post

0 Karma

rsantoso_splunk
Splunk Employee
Splunk Employee

The ES need to import custom apps (phantom) to Enterprise Security. It is believe this has not been setup.

In order to set this up, here are the steps:
1. Go to Enterprise Security > General > App Imports Update > update_es
2. On the Application Regular Expression enter the following at the end:
| (phantom)
The Application Regular Expression will be:
(appsbrowser)|(search)|([ST]A-.)|(Splunk_[ST]A_.)|(DA-ESS-.)|(Splunk_DA-ESS_.)|(phantom)
3. Save this
4. Once you save it, you need to enable the update_es.
On the right hand side of the update_es , you will see the status, click on Enable
5. Now try to again with you Correlation Search, you will find phantom will be in the list of your Adaptive Response Action.
6. Once this is done you can create the Saved search, click on Save and Preview.

For further information on ES App Imports Update:
https://docs.splunk.com/Documentation/ES/4.7.1/Install/ImportCustomApps

0 Karma
Get Updates on the Splunk Community!

Digital Resilience Assessment Launch | How prepared are you for disruption?

Disruption is inevitable. The question is – how prepared are you to handle it? In today’s fast-moving digital ...

Buttercup Games: Further Dashboarding Techniques (Part 2)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Index This | What is the next number in the series? 7,645 5,764 4,576…

February 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...