Splunk Enterprise Security

An error while exporting a Data Model to Phantom

obyazov
New Member

Hello,

I'm trying to export a Data Model from Splunk Free to Phantom using Phantom App. After configuring the necessary fields and clicking Save and Close I get an Error:

Error talking to splunk: POST /servicesNS/nobody/phantom/saved/searches/: status code 400: {"messages":[{"type":"ERROR","text":"Argument \"action.script\" is not supported by this handler."}]}

Does anyone encounter the same problem? Or maybe somebody knows where to look at to solve the problem.

0 Karma

mattsvensson
Engager

ever get an answer?

0 Karma

mattsvensson
Engager

I'm thinking that it's something about being on the free version now and not being able to set permission on the app/index.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...

Splunk Technical Support Is Moving to Cisco Support Tools

Introduction Splunk technical support is transitioning to Cisco’s support environment. This change brings ...