Hi,
I've setup the Phantom App for Splunk and API is connected successfully. So far I've set up some test Saved Search Exports however the CEF extractions don't work, every time I try I get the message:
No matching results found. Configuration has been saved.
So far I have extractions setup for:
username > sourceUser > user name
src_ip > sourceAddress > ip
I can see these fields in the search in Splunk but they wont show in the preview. Any ideas?
In your alert/saved search, do you specify fields to output? (i.e. | fields username, src_ip)
I had to do this for my alert to trigger and for the fields to show up in event forwarding > new saved search export, after clicking 'auto-extract fields'.
Hi JDown3,
I had not done this. Auto-extacted fields now work which is nice to know but I still don't get any extracted results from the preview.
I have the same issue. Update please if you have a solution. thank you
Hi @4A616D6573,
It is the same for me, trying to fix it, let me know if you do. Thanks.