Splunk SOAR (f.k.a. Phantom)

phantom_forward.py called without the correct set of parameters.

markhill1
Path Finder

Hi all, Splunk 7.3.1, ES version 5.3.0, Phantom 4.5.15922.
I have ES configured to use the 'Send to Phantom' action for a couple of correlation searches.
But... I keep seeing this in the _internal logs and no events showing in Phantom.
ERROR phantom_forward:125 - /opt/splunk/etc/apps/phantom/bin/scripts/phantom_forward.py called without the correct set of parameters.
I have tried re-configuring the auth-token, and it tests fine.

Is anyone able to help on this one?
Thanks

Labels (1)
0 Karma

markhill1
Path Finder

After I started ingesting the internal Phantom and Splunk logs into another Splunk machine I did some checking around.
Found that an incorrect label was causing the ingestion errors, but Im still getting the error above, every minute.

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!