Splunk SOAR

Splunk Phantom SOAR Vault tmp Directory Clean Up

splunk4days
Engager

Hello,

 

In short, I have to transmute a file, and I leverage the /vault/tmp/ directory.

 

I'm able to do what I want, but I'm wondering if I have to 'clean up' this /vault/tmp/ directory.

 

ex - I have a file I want to XOR bit by bit. I read unxord.exe bit by bit, write to /vault/tmp/xord.exe, then I do a phantom.vault_add(file_location="/vault/tmp/xord.exe"). This works fine.

 

Do I have to do any removal of the "/vault/tmp/xord.exe"?

 

I've tried to do something like:

import os

os.remove("/vault/tmp/xord.exe")

 

However, I get a path not found error.

 

 So, how often does Phantom SOAR clean up the /vault/tmp/ directory, and can/should I remove the temp file myself?

 

Thanks!

0 Karma

phanTom
SplunkTrust
SplunkTrust

@splunk4days i believe that by using the phantom.vault_add() API the file is "moved" from the tmp dir into the relevant file location on the platform where the vault storage is, rather than copied.

I have not tested this but have also never had to clear the /tmp dir when using it for vault_add() API calls. 

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...