Splunk SOAR

invalid token error while communicating through rest API with phantom using splunk

rajafarhat16
New Member

alt text

Labels (3)
0 Karma

Crypt
Observer

Not OP but my issue was that I'd allowed the wrong IP address. I'd discounted this as a possibility but when I checked the logs on the Phantom server (/var/log/nginx/access.log) I found that the IP of my Splunk server was not what I'd expected (vitulisation messiness).

Thanks to the others in this thread.

0 Karma

cblumer_splunk
Splunk Employee
Splunk Employee

Areas to check:

  1. Automation user on the Phantom side used for the Splunk integration - check the "Allowed IPs" config, this needs to allow for the Splunk search head to communicate with the Phantom host to create new containers/artifacts via the Forwarding Config
  2. Make sure you're entering the entire 'ph-auth-token' value on the Phantom Server Configuration
  3. Check the $splunk_home/var/log/splunk/phantom_configuration.log file for more details

Please post more information to aid in finding a fix.

0 Karma

rajafarhat16
New Member

can anyone here to help me in this regard ?

0 Karma

sam_splunk
Splunk Employee
Splunk Employee

Can you provide more details on what configuration you have set on both sides? Also have you checked out: https://my.phantom.us/4.5/docs/admin/splunk ?

0 Karma

rajafarhat16
New Member

thanks i solved my issue

0 Karma

sam_splunk
Splunk Employee
Splunk Employee

Would you be able to post the details of your fix in case anyone else runs across the same problem?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...