Splunk SOAR

SubSearch Capability of Phantom App

TWiseOne
Path Finder

I have a correlation search that uses 2 sub-searches using the inputlookup & NOT commands for whitelisted devices/IPs.

When I configure the Phantom App Saved Search Export it finds no results.

However if I expand the whole search (CMD+SHIFT+E) it returns results fine.

Are there any limitations to the sub-search capability of the app? If not is there something I am missing in the configuration of the correlation search or Phantom Forwarding config?

cblumer_splunk
Splunk Employee
Splunk Employee

That issue is typically caused by the permissions defined on the Saved Search in question:

Permissions
When the saved search is first created, the configuration is considered private and stored in the user’s directory. For it to be saved in the correct spot and made available to the Phantom app for Splunk for scheduling, the permissions of the saved search need to be modified as follows:

  1. While in context of the saved search app, go to the Settings menu and select ‘Searches, reports, and alerts’.

  2. Select the saved search that you want to make available to the Phantom app for Splunk, for scheduling.

  3. Under Actions, select ‘Edit’ and ‘Edit Permissions’

  4. Change ‘Display For’ to All apps, ‘Run As’ to User, set read/write permissions as appropriate, and click save.

Upon clicking Save, you’ll be dropped back to the ‘Searches, Reports, and Alerts’ screen, where you should now see the Sharing column show ‘Global’ for your search. It will now be available to other apps.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...