Splunk SOAR

"Search Settings" Indexer Host change requires Phantom restart?

jeffrey_berry
Path Finder

In our environment (Phantom version 4.10.3.x), the HEC (HTTP Event Collector) server name that is used as an "Indexer Host" (i.e. Phantom UI field label for the HEC server for a "Distributed Splunk Enterprise Deployment" ) was changed recently. The new server name was entered into the "Indexer Host" field, "Test Connection" was successful, and "reindex" was successful. However later it was noticed that no new event data was being ingested into the Splunk Enterprise phantom* indexes. The resolution was to restart Phantom and "reindex " again for the missing events in the phantom* indexes. It is suspected that the "process" for ingesting new events into the phantom* indexes is not updated with the changes to the  "Indexer Host" field until Phantom is restarted; however, the "processes" for "Test Connection" and "reindex" appeared to work without a Phantom restart. No references that a Phantom restart is required was found in the online documentation.

Does anyone have more on this issue/bug/phenomenon and/or has anyone else experienced this issue/bug/phenomenon? 

Labels (3)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...