Splunk SOAR

Using Splunk Phantom post data to send data from Phantom back into Splunk

davidwaugh
Path Finder

Hi I am new to Splunk Phantom and have so far far

  • Triggered an alert in Splunk
  • This send the data into Phantom
  • Phantom then runs a playbook which queries some Carbon Black stuff
  • I then want to send the results of this carbon black search back into Splunk

I can see that i can use the Splunk App in Phantom and use the postdata command.

However i only seem to be able to sned back one value at a time, with no futher remarks.
Is it possible to send back the complete object from Phantom into Splunk as a JSON object?

For example you would have the original data you sent to Phantom and then the enhancement that you have got from running the playbook against the original data.

The reason is that Splunk is the front end tool, and it would be more convienient to view any results in Splunk.

Labels (3)
0 Karma

ansusabu
Communicator

You can use format block for formatting data and that formatted data can be used to post in SPlunk

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...