Splunk SOAR

Splunk SOAR
Community Activity
johnteo
Hello, I have encountered some issues with configuring applications on Splunk Phantom. How do I obtain API keys/URLs ...
by johnteo Explorer in Splunk SOAR 10-24-2019
0 1
0
1
pedavallis
Hello all, I am trying to clone the azure devops repo into the splunk phantom and getting the following error. Pl, ca...
by pedavallis New Member in Splunk SOAR 10-24-2019
0 1
0
1
johnteo
Hi everyone, I am having trouble locating the documentation on requirements for the hardware, system and network requ...
by johnteo Explorer in Splunk SOAR 10-16-2019
0 1
0
1
ucz350
I was wondering if anyone knows how to install the phantom license key through the cli? Or potentially through some r...
by ucz350 Path Finder in Splunk SOAR 10-14-2019
1 3
1
3
robertbuscato
Results from LDAP query: user1user2 I want to send an email for each of this users with the below email body separate...
by robertbuscato New Member in Splunk SOAR 09-26-2019
0 7
0
7
AlexBryant
I am using Phantom to submit a Splunk query and I can get the results from the action_result.data artifact. Those res...
by AlexBryant Path Finder in Splunk SOAR 09-22-2019
0 3
0
3
sdubey_splunk
We are trying to forward the events to phantom via datamodel export function. when we click on save and preview , we ...
by sdubey_splunk Splunk Employee Splunk Employee in Splunk SOAR 09-18-2019
0 2
0
2
molehu
I searched for the Phantom app for Cisco Threat Response but was unable to find it in Phantom. If such Phantom app ex...
by molehu Engager in Splunk SOAR 09-12-2019
0 0
0
0
davidwaugh
Hi I am new to Splunk Phantom and have so far far Triggered an alert in SplunkThis send the data into PhantomPhantom ...
by davidwaugh Path Finder in Splunk SOAR 09-10-2019
0 1
0
1
fati_ben_soar
Hello, I am using the action Run playbook in Phantom. Splunk can send the alert, but without fields created on Splu...
by fati_ben_soar New Member in Splunk SOAR 08-28-2019
0 1
0
1
borisk95
Using Splunk Phantomm app and trying to export saved data model filds that are INHERITED parsed and can be forwared b...
by borisk95 New Member in Splunk SOAR 08-28-2019
0 1
0
1
bviehmann
here an example: Guten Tag Herr Tobias, Tobias Betroffene Plattform IP: 10.11.12.13, 10.11.12.13 Hostname: 244.abc....
by bviehmann New Member in Splunk SOAR 08-28-2019
0 1
0
1
ansusabu
Do we have retention policy for the containers in Phantom? When there are huge number of containers in Phantom, it co...
by ansusabu Communicator in Splunk SOAR 08-28-2019
0 4
0
4
TWiseOne
I have a correlation search that uses 2 sub-searches using the inputlookup & NOT commands for whitelisted devices/IPs...
by TWiseOne Path Finder in Splunk SOAR 08-28-2019
1 1
1
1
bviehmann
hello I scan systems with nessus on vulnerbilities and send them to splunk. With phantom I could generate emails. An...
by bviehmann New Member in Splunk SOAR 08-28-2019
0 5
0
5
fmh
Hi,we are using Splunk Cloud service and would like to extend it with Phantom.Does anybody know whether this is possi...
by fmh Engager in Splunk SOAR 08-28-2019
2 2
2
2
poctalk
I'm working on building a POC to test gateways with Phantom and I can't seem to get this working. I've created an as...
by poctalk Engager in Splunk SOAR 08-28-2019
1 3
1
3
manrodriguez
Hi guys!! I have to ask the following question about an integration with phantom, I have raised a 7730 checkpoint and...
by manrodriguez Engager in Splunk SOAR 08-28-2019
0 1
0
1
shivinder
Hi I am facing an issue where I continually keep getting a little pop-up at the top right hand side of the Phantom we...
by shivinder Explorer in Splunk SOAR 08-21-2019
2 6
2
6
ansusabu
I have a usecase configured in Splunk and we are getting multiple events in phantom at the same time. When I try to r...
by ansusabu Communicator in Splunk SOAR 08-19-2019
0 0
0
0
markhill1
Hi all, Splunk 7.3.1, ES version 5.3.0, Phantom 4.5.15922. I have ES configured to use the 'Send to Phantom' action f...
by markhill1 Path Finder in Splunk SOAR 08-18-2019
0 1
0
1
e_mazza
Hello, I tried to register 1 year ago without success. I tried again today but it says I’m already registered (but I ...
by e_mazza New Member in Splunk SOAR 08-15-2019
0 2
0
2
ang3la42
Hi, I was hoping someone would be able to let me know the correct role to choose for a user whose responsibility will...
by ang3la42 New Member in Splunk SOAR 08-15-2019
0 1
0
1
sdubey_splunk
Phantom: Can I disable port 80 on phantom server? Is it possible to disable port 80 on Phantom server and what is the...
by sdubey_splunk Splunk Employee Splunk Employee in Splunk SOAR 07-23-2019
0 1
0
1
sdubey_splunk
I am trying to install Phantom app: install digitalshadows-1.0.1 published in Phantom Marketplace (https://my.phantom...
by sdubey_splunk Splunk Employee Splunk Employee in Splunk SOAR 07-23-2019
0 1
0
1
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...