Splunk SOAR (f.k.a. Phantom)

How to select the "create server" button for splunk_app_soar configuration?

TamishaJ
Engager

Have anyone ran across the following issue before? 

I am trying to implement the Splunk SOAR app but we are not able to select the “create server” button. We have referred to the online documentation but we do not see the option to replace each instance of phantom with splunk_app_soar. 

0 Karma
1 Solution

phanTom
SplunkTrust
SplunkTrust

@TamishaJ this sounds like a permissions issue. 

Are you on Splunk Cloud? If so then I believe a few people have had issues seeing the correct permissions group on Splunk Cloud and required support involvement. 

If on-prem, make sure the account has the relevant phantom role(s) in Splunk and you should be able to access the Create Server capability. 

Happy SOARing!

View solution in original post

0 Karma

phanTom
SplunkTrust
SplunkTrust

@TamishaJ this sounds like a permissions issue. 

Are you on Splunk Cloud? If so then I believe a few people have had issues seeing the correct permissions group on Splunk Cloud and required support involvement. 

If on-prem, make sure the account has the relevant phantom role(s) in Splunk and you should be able to access the Create Server capability. 

Happy SOARing!

0 Karma
Get Updates on the Splunk Community!

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...