Getting Data In

Splunk App for Phantom Reporting

VijaySrrie
Builder

Hi Team,

Splunk App for Phantom Reporting

Testing 1 :

If HEC token is created in HF,     Indexes are created in Indexer,    Roles/User/splunk app for phantom reporting app is created in SH ---> In phantom Side - If I give the host as (HF IP) --> It is not working

(Getting error as)
Test connection failed. Test connection failed for phantomsearch on host "Splunk": No results found.

Testing 2:

If indexes are created in Indexer,   HEC token/user/roles/splunk app for Phantom reporting app is created in SH --> In phantom side --> If I give the host as (SH IP) --> It is working (But it is not accepted as best practice)

Testing 3:

Indexes/HEC token/user/role is created in Indexer and splunk app for phantom reporting app is created in SH, In Phantom end --> If I give the host as (Indexer IP) ---> It is working (This is also not accepted as best practice)

What should I do to make my Testing 1 work?

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...