Hi Team,
Testing 1 :
If HEC token is created in HF, Indexes are created in Indexer, Roles/User/splunk app for phantom reporting app is created in SH ---> In phantom Side - If I give the host as (HF IP) --> It is not working
(Getting error as)
Test connection failed. Test connection failed for phantomsearch on host "Splunk": No results found.
Testing 2:
If indexes are created in Indexer, HEC token/user/roles/splunk app for Phantom reporting app is created in SH --> In phantom side --> If I give the host as (SH IP) --> It is working (But it is not accepted as best practice)
Testing 3:
Indexes/HEC token/user/role is created in Indexer and splunk app for phantom reporting app is created in SH, In Phantom end --> If I give the host as (Indexer IP) ---> It is working (This is also not accepted as best practice)
What should I do to make my Testing 1 work?