I am trying to send data from Splunk ES to Phantom
Version is 7.2.6
After downloading Phantom app from Splunk, within that App, in the forwarding option there are 2 selections:
Under event f...
Hello,
I am trying to find a native solution in order to monitor the execution of a Phantom Playbook. In case one of the actions fail, or a specific message/data is returned by a custom function, d...
Hi all, We are currently facing an issue with our Splunk SOAR installation Every time that we open the playbook editor, it shows the errors in the screenshot below and all the dropdown and search f...
Good morning,
I woud like to test SplunkPhantom Community Edition in my home lab. When I try to install it following the documentation, the following error appears:
About to proceed with Phantom...
i have Multiple event forwardings enabled on my Phantom App for Splunk that use saved searches to trigger notable events to phantom. I had recently we upgraded the App from ver 4.0.35 to 4.1.73...
Issue: Phantom Add-on for Splunk – is not saving any changes done on Saved searches and below error is observed in logs internally. Error observed in Internal logs : 2022-11-17 17:19:1...
...xternal Splunk instance (both Indexer & Search head) but the Splunk is on Cloud (saas product) 1. My question is would it support for building the SplunkPhantom with out Splunk embedded i...
I am using Splunk Enterprise and wish to automatically forward events to Phantom. I am able to send events to Phantom with a saved search using the Phantom add-on. However, to send events to Phantom...
...ith this use ease". This answer is that this is my interpretation of the Splunk ES and Phantom integration. I want to be able to use Phantom to collect evidence, conduct additional searches and close t...