Splunk Tech Talks
Deep-dives for technical practitioners.

Super Speed with Phantom Slash Commands

melissap
Splunk Employee
Splunk Employee

View our Tech Talk: Security Edition,  Super Speed with Phantom Slash Commands 

 

Want to accelerate your Phantom investigations and response, without leaving your Command Line Interface (CLI)? Phantom Slash Commands let you do just that. Slash Commands are instructions written into Phantom’s activity pane text box that begin with a forward slash ( / ) followed by a command. These allow you to run playbooks and actions by simply typing into your CLI, saving you time and effort by removing the need for excess mouse clicks. Paired with keyboard navigation from Phantom’s 508 compliance, Slash Commands are a powerful tool for every Phantom user.

With Slash Commands, you can quickly pivot in an investigation to:

  • Run an action
  • Run a playbook
  • Add a note to a container
  • Update or edit a container
  • Get datapath information for use with other actions

...all without ever leaving your CLI.

Tune in to learn:

  • How Slash Commands speed up investigations
  • How to quickly pivot and execute actions, all within the CLI
  • See how Slash Commands and Phantom save you time and effort
Contributors
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...