Splunk SOAR

Tufin Integration with Splunk SOAR for Extended Actions

soar_in
New Member

Hi,

I came across a guide on the official Tufin website detailing the integration between Tufin and SOAR Phantom:

https://extensions.tufin.com/details/tufin-splunk-phantom-integration

This integration offers a range of actions, including the capability to block domains. However, when I checked the Splunk App Store, the available Tufin app seems to have a limited set of actions and does not include the ability to block IPs or domains:

https://splunkbase.splunk.com/app/5859

Is anyone having this app and would be willing to share it? Or if you have developed something similar in the past, could you share some tips?

 

Thanks

Labels (1)
0 Karma

Samu
Explorer

Hi,

I am just facing the same problem. Did you finally figured out any solution? I am dealing with this issue directly with tufin, hope to have an answer soon. I´ll come back if I have any update. 

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...