Hi,
I came across a guide on the official Tufin website detailing the integration between Tufin and SOAR Phantom:
https://extensions.tufin.com/details/tufin-splunk-phantom-integration
This integration offers a range of actions, including the capability to block domains. However, when I checked the Splunk App Store, the available Tufin app seems to have a limited set of actions and does not include the ability to block IPs or domains:
https://splunkbase.splunk.com/app/5859
Is anyone having this app and would be willing to share it? Or if you have developed something similar in the past, could you share some tips?
Thanks
Hi,
I am just facing the same problem. Did you finally figured out any solution? I am dealing with this issue directly with tufin, hope to have an answer soon. I´ll come back if I have any update.