Splunk Enterprise Security

Forwarding Data between Splunk ES and Phantom

rupalekar
Explorer

I am trying to send data from Splunk ES to Phantom

Version is 7.2.6

After downloading Phantom app from Splunk, within that App, in the forwarding option there are 2 selections:

Under event forwarding tab-->

New Data Model Export
OR
New Saved Search Export

When I select 1st option (New Data Model Export) , it doesn't let me go through unless I fill up "Select Object" section
This 'Select Object' is greyed out/has no drop down options

What is this Select Object knob and where do I create an Object so that it becomes selectable over here?

0 Karma
1 Solution

kchamplin_splun
Splunk Employee
Splunk Employee

There's documentation here that has pretty solid detail:
https://my.phantom.us/4.2/docs/admin/splunk

sign up for an account at phantom.us - it's free.

However, the TL;DR is, in order to export data via a data model search, you need datamodels defined in your Splunk instance/search head - those datamodels will then have "objects" in them which should "un-grey out" the "select object" field. If you want a quick test, install the Splunk Common Information Model (CIM) app on your Splunk instance. Restart splunk after install and see if the dropdown is still grey'd out.
https://splunkbase.splunk.com/app/1621/

View solution in original post

0 Karma

kchamplin_splun
Splunk Employee
Splunk Employee

There's documentation here that has pretty solid detail:
https://my.phantom.us/4.2/docs/admin/splunk

sign up for an account at phantom.us - it's free.

However, the TL;DR is, in order to export data via a data model search, you need datamodels defined in your Splunk instance/search head - those datamodels will then have "objects" in them which should "un-grey out" the "select object" field. If you want a quick test, install the Splunk Common Information Model (CIM) app on your Splunk instance. Restart splunk after install and see if the dropdown is still grey'd out.
https://splunkbase.splunk.com/app/1621/

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...