Splunk SOAR

Configuring the Windows Remote Management app with the Splunk SOAR platform

kareem
Explorer
Salam Splunkers,
I’m having a problem while configuring the Windows Remote Management app with the Splunk SOAR platform. When testing the connectivity with the transport type set to NTLM, it fails and displays an error message. Following the error message, I disabled FIPS mode on the Windows Server and tested the connectivity again, but the issue persists. I then changed the transport type to Kerberos, but ran into a different issue.
I have a  few questions:
  1. Is the targeted system for integration with this app the Windows Server or the Windows\Linux endpoint?
  2. Do we need to integrate the Windows Server itself in order to access the endpoints listed under the AD domain of that Windows Server with this app?
Any guidance would be appreciated!
Labels (2)
0 Karma

marnall
Motivator

The targeted server/endpoint for integration with this app is the machine that you would like to run commands on. The server/endpoint itself does not need to be integrated into SOAR, but rather SOAR needs credentials/certificates/tickets to authenticate with the winRM service on the target server/endpoint.

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...