Splunk SOAR

Splunk SOAR
Community Activity
karthikes
Dear Team,I am karthik from prudential singapore, our Phantom UAT server suddenly goes down.when we attempt to restar...
by karthikes New Member in Splunk SOAR 09-18-2020
0 2
0
2
gf13579
The scenario is that I want to wrap around an existing app (ServiceNow) that make it easier for analysts to use manua...
by gf13579 Communicator in Splunk SOAR 09-16-2020
0 2
0
2
fhq
I am wanting to kick off a playbook when the container owner value changes from NULL to Not NULL. So far I have creat...
by fhq New Member in Splunk SOAR 09-16-2020
0 3
0
3
chandraprathi
While compiling and installing the Splunk phantom Application which I have developed, I am getting an error with erro...
by chandraprathi Explorer in Splunk SOAR 09-16-2020
0 8
0
8
brandylee1993
When parsing the email message body for inclusion in the ticket in Jira, parsing fails on special characters or non-A...
by brandylee1993 Explorer in Splunk SOAR 09-16-2020
0 1
0
1
jeffrey_berry
What is best practice for the HEC endpoint(s) for the "Phantom Remote Search" app in a clustered environment?Per the ...
by jeffrey_berry Path Finder in Splunk SOAR 09-16-2020
0 1
0
1
Izzet
Phantom 4.9 supports Markdown notes and it is possible to add markdown note using GUI. But how to use markdown with t...
by Izzet New Member in Splunk SOAR 09-16-2020
0 1
0
1
Izzet
Hi everyone, It might me a silly question  The simplified case. 3 artifacts within the event with 3 different IP add...
by Izzet New Member in Splunk SOAR 09-16-2020
0 1
0
1
Augliv
Hi all,I created a playbook that runs a Splunk search query and I can see in the playbook's debugger and in the event...
by Augliv Loves-to-Learn in Splunk SOAR 09-16-2020
0 1
0
1
linuts
Hello, whenever I try to add a new artifact I got the following errorphantom.act(): 'add_artifact_1' cannot be run on...
by linuts Engager in Splunk SOAR 09-16-2020
0 1
0
1
tbrown110
Hello,I have a playbook that is currently in production and I don't want to randomly test it without asking the quest...
by tbrown110 New Member in Splunk SOAR 09-16-2020
0 1
0
1
gf13579
I've configured a pair of Phantom servers to use warm standby. As per the documentation, I ran ibackup.pyc --setup af...
by gf13579 Communicator in Splunk SOAR 09-16-2020
0 3
0
3
rhugo
Can one use Splunk phantom for auto-remediation?What real-life use cases are applicable to the use of Phantom? 
by rhugo Observer in Splunk SOAR 08-31-2020
0 1
0
1
gf13579
I'm trying to close a Notable in ES from Phantom. I'm using the update event action from the Splunk app (v1.3.41) but...
by gf13579 Communicator in Splunk SOAR 08-19-2020
0 3
0
3
brycekaline
Hi. My request to join the Phantom Community was approved, however the link I was provided has since expired and I ca...
by brycekaline Engager in Splunk SOAR 08-18-2020
1 1
1
1
brandylee1993
How can I Troubleshoot playbook issue where the wrong raw log is being included in the ticket.For example, where tick...
by brandylee1993 Explorer in Splunk SOAR 08-05-2020
0 1
0
1
waleksandrowski
I can't quarantine device by automation. Action "set quarantine approved" failed.  Message:Error from server. Status ...
by waleksandrowski New Member in Splunk SOAR 08-04-2020
0 0
0
0
gf13579
If I try to search phantom container events by label, status or several other fields, I don't see events relating to ...
by gf13579 Communicator in Splunk SOAR 07-29-2020
0 1
0
1
willhart802
I'm very new to Phantom. Can someone provide some guidance or advice for naming playbooks and what has worked or hasn...
by willhart802 Engager in Splunk SOAR 07-23-2020
0 2
0
2
LouisdesVaux
Dear All, I'm testing Splunk Phantom using the Community Edition to evaluate this product that seems great. Configuri...
by LouisdesVaux New Member in Splunk SOAR 07-21-2020
0 0
0
0
clopmz
Good morning, I woud like to test Splunk Phantom Community Edition in my home lab. When I try to install it following...
by clopmz Explorer in Splunk SOAR 07-09-2020
1 4
1
4
gf13579
When I run Get Users against the group named G-SomeGroup it returns just 1 result. The group contains 3 membersI can ...
by gf13579 Communicator in Splunk SOAR 06-23-2020
0 0
0
0
prakashbesra
Hi, I am using Phantom to solve login issue in Okta. If a user is facing login issue in Okta, then I want to create a...
by prakashbesra New Member in Splunk SOAR 06-10-2020
0 1
0
1
garciajd123
Not sure why I get stuck with a "Loading" screen.  Latest version of Splunk.What am I missing? 
by garciajd123 New Member in Splunk SOAR 06-10-2020
0 2
0
2
williamchenyp
I just recently completed the Phantom Admin and Playbook Development training and am in the process of using what I'v...
by williamchenyp Explorer in Splunk SOAR 05-29-2020
0 2
0
2