Splunk Tech Talks
Deep-dives for technical practitioners.

Super Speed with Phantom Slash Commands

melissap
Splunk Employee
Splunk Employee

View our Tech Talk: Security Edition,  Super Speed with Phantom Slash Commands 

 

Want to accelerate your Phantom investigations and response, without leaving your Command Line Interface (CLI)? Phantom Slash Commands let you do just that. Slash Commands are instructions written into Phantom’s activity pane text box that begin with a forward slash ( / ) followed by a command. These allow you to run playbooks and actions by simply typing into your CLI, saving you time and effort by removing the need for excess mouse clicks. Paired with keyboard navigation from Phantom’s 508 compliance, Slash Commands are a powerful tool for every Phantom user.

With Slash Commands, you can quickly pivot in an investigation to:

  • Run an action
  • Run a playbook
  • Add a note to a container
  • Update or edit a container
  • Get datapath information for use with other actions

...all without ever leaving your CLI.

Tune in to learn:

  • How Slash Commands speed up investigations
  • How to quickly pivot and execute actions, all within the CLI
  • See how Slash Commands and Phantom save you time and effort
Get Updates on the Splunk Community!

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...