Getting Data In

PhantomRemoteSearch/Connecttosinglesplunk

VijaySrrie
Builder

Hi,

We are integrating phantom with splunk using below doc

https://docs.splunk.com/Documentation/PhantomRemoteSearch/1.0.14/PhantomRemoteSearch/Connecttosingle...

As per the doc we create two users - phantomsearchuser​ and ​phantomdeleteuser

May I know why these users are created?? what they will do?

Also, as per this --> https://splunkbase.splunk.com/app/4399/#/details  

(A userid is created at phantom end and it is added to below lookup in splunk) --> I have created it as phantom_test at the phantom end. May I know why this user is required?

4- Edit phantomusers.csv file under <Splunk>/etc/apps/splunk_app_phantom/lookups and add new entries. Each entry should map the phantom userid to the phantom username. You can get the userids/username mapping from your Phantom instance under Administration -> User Management -> Users and click on each individual user to get the userid.

Totally I have 3 users (2 users created in splunk and 1 user created in phantom)

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...