Not OP but my issue was that I'd allowed the wrong IP address. I'd discounted this as a possibility but when I checked the logs on the Phantom server (/var/log/nginx/access.log) I found that the IP of my Splunk server was not what I'd expected (vitulisation messiness).
Thanks to the others in this thread.
Areas to check:
$splunk_home/var/log/splunk/phantom_configuration.log
file for more detailsPlease post more information to aid in finding a fix.
can anyone here to help me in this regard ?
Can you provide more details on what configuration you have set on both sides? Also have you checked out: https://my.phantom.us/4.5/docs/admin/splunk ?
thanks i solved my issue
Would you be able to post the details of your fix in case anyone else runs across the same problem?