Splunk SOAR

Phantom | Splunk search does not appear in the result

Augliv
Loves-to-Learn

Hi all,

I created a playbook that runs a Splunk search query and I can see in the playbook's debugger and in the event that it works fine.

In the event, splunk gadget, there are data in the info section, but below in results, it's empty.

What would it be missing or misconfigured?

Capture.JPG

Capture2.JPGCapture3.JPG

 

Cheers!

Labels (2)
0 Karma

phanTom
SplunkTrust
SplunkTrust

@Augliv this is a known bug with the current version of the Splunk app on Phantom. If you are a customer you can request a BETA app from Support, otherwise you will have to wait for the fixed release. 
As you have seen, the results come through and can be used downstream in playbooks, but the widget doesn't display the results. Recently had exactly the same issue at 1 customers and can confirm the BETA app resolves the issues.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...