Splunk SOAR (f.k.a. Phantom)

Phantom environment is not stable occasionally !

saikiran334
Explorer

1) We have installed Phantom on Linux server and while executing playbooks in automation mode ,Our platform is getting hanged occasionally and stops all playbooks execution , so that we could not able to execute playbooks continuously.
2) so eventually each playbook keeps on spinning for hours and hours , at that time we are restarting "DECIDED" from System health tab , at that moment everything goes normal.

we are not sure which specific process/activity causing this behavior?

Labels (3)
Tags (1)
0 Karma

mjuestel2
Explorer

I would also take a hard look at your existing playbooks, to see where they are failing. Might be time to optimize them further and follow best practices.

0 Karma

phantom_mhike
SplunkTrust
SplunkTrust

There are a couple issues that can cause this but if your issues is repeatable, I would suggest opening a support ticket and submitting logs every time a hang like this happens. I have gone through this a couple of times now and tracking down the problems that can cause this can be challenging. There are a few fixes coming up in the next version that may resolve your problem but dont bank on that. Get a support ticket going.

BEFORE you restart:
• Collect all the logs from /var/log/phantom and /var/log/nginx
• Save the json from https:///rest/playbook_run?_filter_status="running"
• Save the json from https:///rest/action_run?_filter_status="running"
Once these are collected, you can restart and submit these files to a support ticket

Keep in mind that when phantom is restarted, all queued containers that have not been run yet and those that are currently actively running will be canceled and will not be re-queued when phantom comes back online. Its a good idea to get a script up and running to re-run all of those "lost" containers.

0 Karma

saikiran334
Explorer

thanks @phantom_mhike , we opened case with Phantom and provided debug logs , as of now they found some issue in playbook app configuration , current status is in progress

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...