Splunk SOAR (f.k.a. Phantom)

How do I perform field mapping between Splunk and Phantom when using Run playbook in Phantom ?

fati_ben_soar
New Member

Hello,

I am using the action Run playbook in Phantom. Splunk can send the alert, but without fields created on Splunk. I have created the same fields on Phantom but the mapping was not performed.

0 Karma

cblumer_splunk
Splunk Employee
Splunk Employee

Using the Phantom App for Splunk would be recommended for performing field mappings in that way:
https://splunkbase.splunk.com/app/3411/

You can utilize either a Saved Search or Data Model to have events from Splunk Core/ES which meet the defined criteria in your SPL forwarded to the Phantom instance of your choice:

alt text

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...