Splunk SOAR

How do I perform field mapping between Splunk and Phantom when using Run playbook in Phantom ?

fati_ben_soar
New Member

Hello,

I am using the action Run playbook in Phantom. Splunk can send the alert, but without fields created on Splunk. I have created the same fields on Phantom but the mapping was not performed.

0 Karma

cblumer_splunk
Splunk Employee
Splunk Employee

Using the Phantom App for Splunk would be recommended for performing field mappings in that way:
https://splunkbase.splunk.com/app/3411/

You can utilize either a Saved Search or Data Model to have events from Splunk Core/ES which meet the defined criteria in your SPL forwarded to the Phantom instance of your choice:

alt text

0 Karma
Get Updates on the Splunk Community!

AppDynamics is now part of Splunk Ideas

Hello Splunkers, We have exciting news for you! AppDynamics has been added to the Splunk Ideas Portal. Which ...

Advanced Splunk Data Management Strategies

Join us on Wednesday, May 14, 2025, at 11 AM PDT / 2 PM EDT for an exclusive Tech Talk that delves into ...

Uncovering Multi-Account Fraud with Splunk Banking Analytics

Last month, I met with a Senior Fraud Analyst at a nationally recognized bank to discuss their recent success ...