Splunk Enterprise Security

An error while exporting a Data Model to Phantom

obyazov
New Member

Hello,

I'm trying to export a Data Model from Splunk Free to Phantom using Phantom App. After configuring the necessary fields and clicking Save and Close I get an Error:

Error talking to splunk: POST /servicesNS/nobody/phantom/saved/searches/: status code 400: {"messages":[{"type":"ERROR","text":"Argument \"action.script\" is not supported by this handler."}]}

Does anyone encounter the same problem? Or maybe somebody knows where to look at to solve the problem.

0 Karma

mattsvensson
Engager

ever get an answer?

0 Karma

mattsvensson
Engager

I'm thinking that it's something about being on the free version now and not being able to set permission on the app/index.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...