Hi all, I’m just about to upgrade our Phantom / Splunk SOAR version to 5.0.1. The Version Compatibility matrix in the documentation for thePhantomRemoteSearchapp suggests that this version i...
What is best practice for the HEC endpoint(s) for the "PhantomRemoteSearch" app in a clustered environment? Per the instructions in the url below for configuring the "PhantomRemoteSearch" app...
...xternal Splunk instance (both Indexer & Search head) but theSplunk is on Cloud (saas product) 1. My question is would it support for building theSplunkPhantom with out Splunk embedded i...
I use "theSplunkPhantomRemoteSearchapp" to connect thePhantom to theSplunk Enterprise, it works fine until after migrating theSplunk indexer cluster to new servers, my Phantom stop forward l...
I have not been able to see any of the logs in splunk that we are supposed to. We added thePhantomremotesearchapp to splunk and have it configured, but i am not able to see a connection p...
Does thePhantomRemoteSearchapp get installed on my Enterprise Security Search Head, a HEC server, or another server all together? Seems there are search, HEC inputs, and index portions yet it's o...
We have a well established Splunkapp on an instance which is serving as a Search Head and an Indexer. However, there are some data there which needs to be forwarded to some other site, which hosts a...
...reate their own saved search exports, however, don't want them to see each other's export details.
So basically my problem is that if I give their Splunk users permissions to thePhantomappthen they c...
Hi, I would like to know if there is the possibility to automatically trigger a playbook when there is a change in the status of a container (e.g. when it becomes "Closed")? Thank you in advance!