Thread Info | |||||
---|---|---|---|---|---|
when the original syslog was forwarded to phantom, some key filed(like srcIP/dstIP) was missing artifact. these key...
by
Qingguo
Engager
in
Splunk SOAR (f.k.a. Phantom)
07-29-2021
|
0
|
1
| |||
After integration with ISE 2.4 successfully , I test action of quarantine for a device , phantoms shows it has been ...
by
Qingguo
Engager
in
Splunk SOAR (f.k.a. Phantom)
07-29-2021
|
0
|
0
| |||
I'm attempting to pass a variable/value between custom functions in a playbook. I've done this before without issue, ...
by
Mr
Loves-to-Learn Lots
in
Splunk SOAR (f.k.a. Phantom)
07-23-2021
|
0
|
0
| |||
hi phantom team,I have a simple use case to rename a filename in vault.As its immutable, I copied the contents to vau...
by
sunilpanda023
Path Finder
in
Splunk SOAR (f.k.a. Phantom)
07-21-2021
|
0
|
0
| |||
Hi All,
I am quite new to Phantom. I have written few plabooks which works perfectly as intended when run from the ...
by
shaquibk
Explorer
in
Splunk SOAR (f.k.a. Phantom)
07-12-2021
|
0
|
2
| |||
Hi All,
Is there a way to simultaneously/bulk respond to multiple notifications generated by prompt actions, or an ...
by
PistolShrimp
Engager
in
Splunk SOAR (f.k.a. Phantom)
06-11-2021
|
0
|
1
| |||
Hi,
I am looking send an email to user with simple yes/no response which I can then use to handle the case. I k...
by
rodneyjerome
Explorer
in
Splunk SOAR (f.k.a. Phantom)
07-01-2021
|
0
|
1
| |||
Hi All,
Good Day!!
This is an Splunk Phantom Architecture question, which we are in the intial stage of building ...
by
YeswanthReddy
Engager
in
Splunk SOAR (f.k.a. Phantom)
06-29-2021
|
0
|
3
| |||
I am noticing for some of our events our playbooks run multiple times on the same event. How can I go about keeping t...
by
crayford
Explorer
in
Splunk SOAR (f.k.a. Phantom)
06-29-2021
|
0
|
2
| |||
Hi,
I would like to know if we change the status of incident on Splunk Phantom, can we automatically notify user?
...
by
eye893
New Member
in
Splunk SOAR (f.k.a. Phantom)
06-27-2021
|
0
|
1
| |||
I am able to run an action (whois ip from whois app) successfuly. However, if i put this action as part of a playboo...
by
brunofernandez
Explorer
in
Splunk SOAR (f.k.a. Phantom)
02-14-2019
|
0
|
5
| |||
Hi team,
I'm using Phantom to create playbooks and I would like to know how the find artifact is used when I cr...
by
MimiThePrince
New Member
in
Splunk SOAR (f.k.a. Phantom)
06-03-2021
|
0
|
1
| |||
- Would you consider it a best practice to type a password into a prompt from a 3rd party script?
- What if the 3rd...
by
bearcat
Engager
in
Splunk SOAR (f.k.a. Phantom)
06-07-2021
|
1
|
0
| |||
Our Phantom's DECIDED process often crashes for performance reasons.
We suspect this is caused by the low number of...
by
PwC-Kimmy
Explorer
in
Splunk SOAR (f.k.a. Phantom)
05-19-2021
|
0
|
1
| |||
Hi,
I would like to know if there is the possibility to automatically trigger a playbook when there is a change in ...
by
drew19
Path Finder
in
Splunk SOAR (f.k.a. Phantom)
05-05-2021
|
0
|
5
| |||
Introduction
Splunk Phantom ingests objects from connected assets, such as your firewall, services like VirusTotal...
by
mconverse_splun
Splunk Employee
in
Splunk SOAR (f.k.a. Phantom)
05-06-2021
|
0
|
0
| |||
This article applies to Splunk Phantom versions 4.6 , 4.5 , 4.2 , 4.1 , 4.0 , 3.5 , 3.0 , 2.1 , 2.0
...
by
kevinh_splunk
Splunk Employee
in
Splunk SOAR (f.k.a. Phantom)
04-23-2021
|
0
|
0
| |||
This article describes a workaround when you run a playbook and see the "user parameter must be of type string" error...
by
kevinh_splunk
Splunk Employee
in
Splunk SOAR (f.k.a. Phantom)
04-23-2021
|
0
|
0
| |||
NOTE: These steps were verified using Phantom version 4.2.7532 and Splunk Universal Forwarder version 7.2.6.
Networ...
by
kevinh_splunk
Splunk Employee
in
Splunk SOAR (f.k.a. Phantom)
04-23-2021
|
0
|
0
| |||
In some cases, the Splunk Phantom virtual appliance can lose its time synchronization with the system time. For examp...
by
kevinh_splunk
Splunk Employee
in
Splunk SOAR (f.k.a. Phantom)
04-22-2021
|
0
|
0
|