Splunk SOAR (f.k.a. Phantom)

Phantom_retry KV Store - How to manage it?

victor_menezes
Path Finder

Hey folks,

Did anyone ever faced a challenge on having hundreds of thousands of events stuck in phantom_retry kv store that are aged enough?
I see in the logs that quite often Splunk complains about the size of phantom_retry and I would like to see/clean up that queue and move on from there. Any idea?

I looked over the documents and there is no instruction on that matter.

Also, if I do "| inputlookup phantom_retry_lookup" it returns nothing. Using the lookup editor app I can only see this empty as well.

Any clue?


Thanks!

Labels (3)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf24, and Community Connections

Thank you to everyone in the Splunk Community who joined us for .conf24 – starting with Splunk University and ...

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...