Splunk SOAR

Tufin Integration with Splunk SOAR for Extended Actions

soar_in
New Member

Hi,

I came across a guide on the official Tufin website detailing the integration between Tufin and SOAR Phantom:

https://extensions.tufin.com/details/tufin-splunk-phantom-integration

This integration offers a range of actions, including the capability to block domains. However, when I checked the Splunk App Store, the available Tufin app seems to have a limited set of actions and does not include the ability to block IPs or domains:

https://splunkbase.splunk.com/app/5859

Is anyone having this app and would be willing to share it? Or if you have developed something similar in the past, could you share some tips?

 

Thanks

Labels (1)
0 Karma

Samu
Explorer

Hi,

I am just facing the same problem. Did you finally figured out any solution? I am dealing with this issue directly with tufin, hope to have an answer soon. I´ll come back if I have any update. 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...