Splunk SOAR (f.k.a. Phantom)

Can the Automation Broker be installed on a virtual machine?

shanto12
New Member

I was wondering if anyone has experience installing the AB on a virtual machine? Is this possible? What are the challenges faced if there are any? There is nothing in the doc about this. Thanks in advance.

Labels (1)
0 Karma

CS_
Path Finder

Yes you can. We have several Virtual servers running on ESXi, and we have broker docker containers running on them. The only issues we're experiencing is occasional errors in SOAR that say "Failed to communicate with Automation Broker" - which I think is a result of our corporate network more than anything else.

But as long as your VM can communicate with SOAR, I can't see any reason why a broker wouldn't work on the VM.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...