Splunk SOAR (f.k.a. Phantom)

Phantom 3.5.x Adaptive Response Action in Splunk ES 5.1

claudiocruz
Engager

I'm trying to integrate Splunk ES 5.1 running on Splunk Core 7.1.

I have the Phantom app configured, connected to the Phantom server (not sending events every second but working when I send it to Phantom on the preview).
Events are in Phantom from Splunk ES, and there are no playbooks at this time.
What I would like to do is to configure a Responsive Action to be set from the Incident that will interact with Phantom. When I go to the incident > Action > Run Adaptive Response Actions, I'm prompted to:

Select actions to run.
+ Add New Response Action

However there are no Response Actions available for Phantom (the Phantom app is installed and configured)

Questions:
Should I see the Adaptive Response for Phantom in Splunk ES to be selected and ran from my Incident Actions?

If now, where would I get the Adaptive Response Action for Phantom?
Is there any documentation on how to create this type of Adaptive Response? (Phantom specific)

Any help, hints, guidance is highly appreciated.

Thanks,
CC

Labels (2)
Tags (1)
0 Karma

Fr4g3r
New Member

Hi,

Has anyone faced this issue and resolved?

Please help as I am also facing the same?

Regards
Shyam

0 Karma

jamesbanach
New Member

Try this documentation link, see if that helps.
https://my.phantom.us/kb/58/

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...