- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Forwarding Splunk events to Phantom automatically
Hi ,
I have integrated splunk with Phantom and can send the events to phantom by clicking on send to Phantom button. But I have scheduled search to send the events to Phantom whenever there is any. However I dont see any events sent to Phantom . I checked the logs, didnt find any error too. Please guide .
Thanks,
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Try using a schedule instead of real time.
https://answers.splunk.com/answers/813705/automatically-forward-events-to-phantom.html#answer-815991
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Hi @rishma,
Did you check out this guide ?
Cheers,
David
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi David @DavidHourani,
yes I have setup the alerts based on this doc. But facing this issue. Manual clicking on send to phantom works fine. But schedule and automatically sending the results to phantom is not working.
Thanks
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you can, share the screenshot of the configuration that you have done
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you .
I see no errors but I see result_count = 0 in the logs alert_actions=""
When I manually run that command or refresh the page after I click on recent results, it shows me the results in search bar. I tried putting that in admin user also. Didnt work.
Phantom configuraiton is working fine as I can send the results by clickind on send to phantom.
Found another way to do it by trigger action . Thats working fine. But with Savesearch Export using phantom app is not working .
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Did you check internal phantom logs and/or scheduler. Have a look at index=_internal yourSavedSearchName
and see if the action field is triggering when it comes to the saved search you're running.
