I had encountered another issue. Adaptive response action GUI on my search head says that the search hasn't returned any results to populate phantom instance & playbook dropdown. After a little research, I had figured out that the search is delegated to the indexer, which doesn't have the phantom instance configured.
To solve it, search need to be run locally, on the search head or phantom needs to be configured on indexing layer as well.
I took the easy way and changed the runphantomplaybook.html and sendtophantom.html and add splunk_server=local before the pipe.
... View more