Splunk SOAR (f.k.a. Phantom)

How to separate saved search exports in Phantom app for different Splunk users?

noysherer
Explorer

I work in an environment where there are different projects for different developers. I want each project to receive events from Splunk (enterprise) alerts to Phantom, and for the developers to create their own saved search exports, however, don't want them to see each other's export details.

So basically my problem is that if I give their Splunk users permissions to the Phantom app then they can see all of the exports, and I can't be the one that creates all of their exports because each project has dozens.

Is there maybe a more efficient way to send events from Splunk enterprise to Phantom without using the exports?

Thank you for your help.

Labels (3)

sbrant_splunk
Splunk Employee
Splunk Employee

If you're not using Splunk Enterprise Security, then there is no Notable ID to send to Phantom. In this case, if you're just using Splunk Enterprise (core), you can use an Adaptive Response action that is provided with the Phantom app for Splunk (https://splunkbase.splunk.com/app/3411/) to forward your alerts. You can choose either "Send to Phantom" or "Run Playbook in Phantom". The documentation is at https://my.phantom.us/4.2/docs/admin/splunk

Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...