Splunk SOAR (f.k.a. Phantom)

Symantec Enpoint Protection 14 Phantom App


While I was checking the SEP 14 Phantom app, 'test connectivity' was working fine, but when it comes to 'Scan endpoint' action even if I have full access it showing as "API failed. Status code: 401 Detail: You do not have permission to retrieve the list of domains." Can anyone help me to resolve the issue?

Labels (2)
Tags (2)


yeah, Phantom is, kind of new tool(in 2020), so, we may not be having enough responses from community members. you may need to contact phantom support only!.


Best Regards,


Tags (4)
0 Karma


Hi @ansusabu  did you ever resolve this? I am getting the exact same error with SEP14.



I was able to resolve this issue with support. If you ever run into this, ensure the account you are using has 'Super Administrator' rights in SEP. Any other level of administrator does not have the permission to use REST API calls. Thanks

Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...