Splunk SOAR

splunk phantom install license key cli

ucz350
Path Finder

I was wondering if anyone knows how to install the phantom license key through the cli? Or potentially through some rest command. Just started looking into it so maybe there is a straight forward answer documented that I have not found yet but if anyone already knows the answer that would be much appreciated!
The GUI process is straight forward: admin Administration > company settings > license > upload key

Labels (1)
Tags (1)

rplas
Explorer

I believe the only option at the moment is to upload the license file through the GUI

ivanreis
Builder

I never installed the Phantom license previously, thus I assume the process to add the license should be same as the other Splunk Premium apps.
Here is the command to add a license key thought the cli. Make sure you are logged in Master license and the license key is already downloaded to this server.

./ splunk add licenses {path_to_license_file}

I found this document to run the license thought rest api, but I never run this before

check this link please : https://docs.splunk.com/Documentation/Splunk/7.3.2/RESTREF/RESTlicense#licenser.2Flicenses

0 Karma

ucz350
Path Finder

I am more looking for when running phantom. Meaning, not installed as an app in Splunk. Thanks for the response though.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...