Splunk SOAR

Phantom environment is not stable occasionally !

saikiran334
Explorer

1) We have installed Phantom on Linux server and while executing playbooks in automation mode ,Our platform is getting hanged occasionally and stops all playbooks execution , so that we could not able to execute playbooks continuously.
2) so eventually each playbook keeps on spinning for hours and hours , at that time we are restarting "DECIDED" from System health tab , at that moment everything goes normal.

we are not sure which specific process/activity causing this behavior?

Labels (3)
Tags (1)
0 Karma

mjuestel2
Path Finder

I would also take a hard look at your existing playbooks, to see where they are failing. Might be time to optimize them further and follow best practices.

0 Karma

phantom_mhike
SplunkTrust
SplunkTrust

There are a couple issues that can cause this but if your issues is repeatable, I would suggest opening a support ticket and submitting logs every time a hang like this happens. I have gone through this a couple of times now and tracking down the problems that can cause this can be challenging. There are a few fixes coming up in the next version that may resolve your problem but dont bank on that. Get a support ticket going.

BEFORE you restart:
• Collect all the logs from /var/log/phantom and /var/log/nginx
• Save the json from https:///rest/playbook_run?_filter_status="running"
• Save the json from https:///rest/action_run?_filter_status="running"
Once these are collected, you can restart and submit these files to a support ticket

Keep in mind that when phantom is restarted, all queued containers that have not been run yet and those that are currently actively running will be canceled and will not be re-queued when phantom comes back online. Its a good idea to get a script up and running to re-run all of those "lost" containers.

0 Karma

saikiran334
Explorer

thanks @phantom_mhike , we opened case with Phantom and provided debug logs , as of now they found some issue in playbook app configuration , current status is in progress

0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...