Splunk Enterprise

send to soar inactive in ACTION

dragon
Engager

Hello guys.

I'm having a problem right now.

SOAR : 192.168.100.120 (on-prem, Ver 7)

Splunk Enterprise : 192.168.100.128 (on-prem, Ver 10)

 

I'll tell you a few things I've done so far.

1. Install SOAR App, Connected to SOAR, Created Indexes

dragon_1-1763000363907.png

 

2. also, The connection test from SOAR to Enterprise also went smoothly.

dragon_2-1762998986134.png

3. user prev

dragon_0-1763000346317.png

 

 

However, when I set ‘Send to SOAR’ as an Action in Splunk, the button doesn't activate.

dragon_0-1762995723655.png

 

 

 

Did I miss anything?

 

0 Karma
1 Solution

dragon
Engager

no I dont have any results...

 

but I solved it. thanks

 

first. install both app (SOAR, SOAR EXPORT)

second. setting BOTH OF ALL...

View solution in original post

0 Karma

livehybrid
SplunkTrust
SplunkTrust

HI @dragon 

Do you get anything if you run the following in SPL?

| rest /servicesNS/nobody/phantom/target_list_ar

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

dragon
Engager

no I dont have any results...

 

but I solved it. thanks

 

first. install both app (SOAR, SOAR EXPORT)

second. setting BOTH OF ALL...

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...