Splunk SOAR (f.k.a. Phantom)

Approval manual task without login to Phantom

harishlnu
Engager

Hi Team,

Could you please help me on below requirement, how to make manual task approval without  approver login to the phantom.

Thanks in advance

Regards,

Harisha

Labels (1)
0 Karma

marnall
Builder

You could hit the REST endpoint for approvals. (https://docs.splunk.com/Documentation/SOARonprem/6.2.1/PlatformAPI/RESTApproval) Unfortunately the docs do not include the POST requests for actually approving the task, so you'll have to do an approval in the web interface and then log the POST request using your browser dev tools.

Then you can use that POST request to approve tasks without having to log into SOAR. You will need to provide authentication credentials or a token though.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...