Splunk SOAR

Tufin Integration with Splunk SOAR for Extended Actions

soar_in
New Member

Hi,

I came across a guide on the official Tufin website detailing the integration between Tufin and SOAR Phantom:

https://extensions.tufin.com/details/tufin-splunk-phantom-integration

This integration offers a range of actions, including the capability to block domains. However, when I checked the Splunk App Store, the available Tufin app seems to have a limited set of actions and does not include the ability to block IPs or domains:

https://splunkbase.splunk.com/app/5859

Is anyone having this app and would be willing to share it? Or if you have developed something similar in the past, could you share some tips?

 

Thanks

Labels (2)
0 Karma

Samu
Explorer

Hi,

I am just facing the same problem. Did you finally figured out any solution? I am dealing with this issue directly with tufin, hope to have an answer soon. I´ll come back if I have any update. 

0 Karma
Get Updates on the Splunk Community!

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...

Stay Connected: Your Guide to February Tech Talks, Office Hours, and Webinars!

💌Keep the new year’s momentum going with our February lineup of Community Office Hours, Tech Talks, ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...