- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How do I perform field mapping between Splunk and Phantom when using Run playbook in Phantom ?
fati_ben_soar
New Member
02-14-2019
02:55 AM
Hello,
I am using the action Run playbook in Phantom. Splunk can send the alert, but without fields created on Splunk. I have created the same fields on Phantom but the mapping was not performed.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

cblumer_splunk

Splunk Employee
08-28-2019
11:32 PM
Using the Phantom App for Splunk would be recommended for performing field mappings in that way:
https://splunkbase.splunk.com/app/3411/
You can utilize either a Saved Search or Data Model to have events from Splunk Core/ES which meet the defined criteria in your SPL forwarded to the Phantom instance of your choice:
