- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Phantom | Splunk search does not appear in the result
Augliv
Loves-to-Learn
09-08-2020
08:48 AM
Hi all,
I created a playbook that runs a Splunk search query and I can see in the playbook's debugger and in the event that it works fine.
In the event, splunk gadget, there are data in the info section, but below in results, it's empty.
What would it be missing or misconfigured?
Cheers!
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
phanTom
![SplunkTrust SplunkTrust](/html/@E48BE65924041B382F8C3220FF058B38/rank_icons/splunk-trust-16.png)
SplunkTrust
09-16-2020
02:22 AM
@Augliv this is a known bug with the current version of the Splunk app on Phantom. If you are a customer you can request a BETA app from Support, otherwise you will have to wait for the fixed release.
As you have seen, the results come through and can be used downstream in playbooks, but the widget doesn't display the results. Recently had exactly the same issue at 1 customers and can confirm the BETA app resolves the issues.
![](/skins/images/89D5ADE867CBAF0B5A525B7E23D83D7E/responsive_peak/images/icon_anonymous_message.png)