Splunk SOAR

phantom_forward.py called without the correct set of parameters.

markhill1
Path Finder

Hi all, Splunk 7.3.1, ES version 5.3.0, Phantom 4.5.15922.
I have ES configured to use the 'Send to Phantom' action for a couple of correlation searches.
But... I keep seeing this in the _internal logs and no events showing in Phantom.
ERROR phantom_forward:125 - /opt/splunk/etc/apps/phantom/bin/scripts/phantom_forward.py called without the correct set of parameters.
I have tried re-configuring the auth-token, and it tests fine.

Is anyone able to help on this one?
Thanks

Labels (1)
0 Karma

markhill1
Path Finder

After I started ingesting the internal Phantom and Splunk logs into another Splunk machine I did some checking around.
Found that an incorrect label was causing the ingestion errors, but Im still getting the error above, every minute.

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...