Getting Data In

How to pull data from elasticsearch to Phantom?

amol
New Member
I have elasticsearch database installed on one server. I am trying to pull data from elasticsearch to phantom SOAR. Connectivity between elasticsearch app and phantom is working fine but, I am getting following error while pulling data from elasticsearch.
 
Loaded action execution configuration
Successfully added containers: 0, Successfully added artifacts: 0
1 action failed Unable to load query json. Error: Expecting value: line 1 column 1 (char 0)
 
Configuration:
amol_0-1647327153349.png

 

Labels (2)
0 Karma

bambarita
Observer

have find the answer to solve this?

0 Karma
Get Updates on the Splunk Community!

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...