Splunk Enterprise Security

Investigations in ES vs Phantom

PebbleHG
Engager

In recent discussions with Splunkers and customers, I keep hearing about how the plan is to launch investigations in Phantom. In the recent past, all I ever heard was about how ES was the location where investigations should be managed, due to the provided investigative workbench framework. I've got zero experience with Phantom, and generic statements about investigative features in both products, leaves me confused.

  1. Do investigations mean the same thing in ES and Phantom? If so, is there a compare/contrast about what each product provides?
  2. Assuming both products are capable of allowing analysts to launch an investigation, and the customer owns both products: does Splunk have a preferred recommendation?

matthaios
Engager

This is something I have been trying to figure out as well. The way I see it as I am learning both products is that with Splunk ES, investigations work well adding context and artifacts from searches within your Splunk environment. You can gain insight and context around an event from your log sources, but it doesn't work well with external intel like data enrichment from VirusTotal for example.

With Phantom, Splunk ES notable events seem to be your primary source of events in Phantom and the platform allows you to add context and intel from external sources. Phantom can run reputation of artifacts and display the results really well. It can also easily detonate files and URLs and provide findings, which can also have automated actions taken from the results of any of those actions. It doesn't seem like it can easily provide statistical data from your event logs though. Splunk has swimlanes and timecharts for example that might show trends and anomalies over time.

My hope is to see more integration between the two products. I would like to see Phantom integrated in to the Splunk ES investigation workbench or bring some of the Splunk dashboards over to Phantom more easily. I feel like both products have two separate pieces of the same puzzle and there are advantages and disadvantages to using either product as your primary alerting source.

mjuestel2
Path Finder

I believe the future is to make Phantom the single-pane of glass. We too have ES and Phantom, and are trying to best figure out how to best leverage these products.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...