Splunk SOAR

Tufin Integration with Splunk SOAR for Extended Actions

soar_in
New Member

Hi,

I came across a guide on the official Tufin website detailing the integration between Tufin and SOAR Phantom:

https://extensions.tufin.com/details/tufin-splunk-phantom-integration

This integration offers a range of actions, including the capability to block domains. However, when I checked the Splunk App Store, the available Tufin app seems to have a limited set of actions and does not include the ability to block IPs or domains:

https://splunkbase.splunk.com/app/5859

Is anyone having this app and would be willing to share it? Or if you have developed something similar in the past, could you share some tips?

 

Thanks

Labels (1)
0 Karma

Samu
Explorer

Hi,

I am just facing the same problem. Did you finally figured out any solution? I am dealing with this issue directly with tufin, hope to have an answer soon. I´ll come back if I have any update. 

0 Karma
Get Updates on the Splunk Community!

Why You Can't Miss .conf25: Unleashing the Power of Agentic AI with Splunk & Cisco

The Defining Technology Movement of Our Lifetime The advent of agentic AI is arguably the defining technology ...

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...