Splunk SOAR

Tufin Integration with Splunk SOAR for Extended Actions

soar_in
New Member

Hi,

I came across a guide on the official Tufin website detailing the integration between Tufin and SOAR Phantom:

https://extensions.tufin.com/details/tufin-splunk-phantom-integration

This integration offers a range of actions, including the capability to block domains. However, when I checked the Splunk App Store, the available Tufin app seems to have a limited set of actions and does not include the ability to block IPs or domains:

https://splunkbase.splunk.com/app/5859

Is anyone having this app and would be willing to share it? Or if you have developed something similar in the past, could you share some tips?

 

Thanks

Labels (2)
0 Karma

Samu
Explorer

Hi,

I am just facing the same problem. Did you finally figured out any solution? I am dealing with this issue directly with tufin, hope to have an answer soon. I´ll come back if I have any update. 

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...