Splunk SOAR (f.k.a. Phantom)

Phantom Play Book Editor, Debugger Problem. Please Help

johnteo
Explorer

For all of the playbooks I have executed and tried to test in the past 24 hours, none of them have successfully executed although no changes have been made to them and they worked fined previously.

The only output at Phantom would be Status: Running. However, upon further inspection the count of failures for running that playbook is increased by 1 for every time I test it.

All the assets are healthy and I have not exceeded he maximum number of actions. I would very much appreciate any assistance and insights offered!

Labels (1)
Tags (1)
0 Karma

ansusabu
Communicator
0 Karma

phantom_mhike
Path Finder

The playbook editor and debugger have a lot of browser side processing going on and caching can cause issues especially after upgrades. That would be my first check. Clear browsing data or try an incognito tab and see if you have the same issue in the debugger.

If the issue persists, go to the container you were debugging against and click on the elipsis next to the playbook in the activity pane and look at the debug log there. If you still dont see the debug logs in this view, then there is something substantially wrong with your phantom instance. If you do see logs here, then this is almost certainly a browser caching issue. Clear all the browser datas and try again or test with a different browser.

0 Karma

johnteo
Explorer

I have cleared all browser datas and tried testing again with different browsers as suggested.

I am also able to view the activity logs, however the same problem still persists whereby the testing is stuck at Status: Running. Could there be any other problems that could have caused this and methods to resolve it?

0 Karma

phantom_mhike
Path Finder

If it isnt a browser issue then my next shot would be to tail the logs at /var/log/phantom and look for any exception thrown while you try running the playbook.

This is not normal behavior at all. What phantom version are you on?

0 Karma

johnteo
Explorer

All is well. I have managed to restart the server and the issue went away alongside it. Thank you so much

0 Karma

johnteo
Explorer

This applies to all the playbooks that I try and execute

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...