Splunk® Phantom (Legacy)

Install and Upgrade Splunk Phantom

Acrobat logo Download manual as PDF


This documentation does not apply to the most recent version of Splunk® Phantom (Legacy). For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

General system requirements

Splunk Phantom requires certain minimum system requirements. Your environment must meet or exceed these requirements. This section details operating systems, web browsers, system storage, Linux file systems, and other requirements for operating Splunk Phantom.

Supported operating systems

Splunk Phantom supports these operating systems and versions:

  • Red Hat Enterprise Linux 6.10
  • Red Hat Enterprise Linux 7.6 through 7.9
  • CentOS 6.10
  • CentOS 7.6 through 7.9

As a rule of thumb, Splunk Phantom generally supports the most recent minor version of a Red Hat Enterprise Linux or CentOS 7 operating system.

Supported browsers

Use the latest, fully patched version of your browser. Splunk Phantom requires a web browser that supports HTML 5, SVG graphics, and TLS.

Splunk Phantom supports these web browsers:

  • Google Chrome
  • Mozilla Firefox
  • Microsoft Internet Explorer 11
  • Microsoft Edge
  • Safari

Supported file systems and required directories

Splunk Phantom supports any file system where the user account running the application can be given write permissions.

In a clustered environment, Splunk Phantom implements GlusterFS for its file shares. If your organization requires a different file system for your Splunk Phantom cluster, make sure that the user account running Splunk Phantom has write permissions to the required directories.

Required directories for a standard installation:

  • /opt/phantom/apps
  • /opt/phantom/bin (spawn and spawn3 daemons)
  • /opt/phantom/local_data/app_states
  • /opt/phantom/scm
  • /opt/phantom/vault
  • /opt/phantom/tmp/shared

Required directories for an installation as an unprivileged user:

  • <phantom_install_dir>/apps
  • <phantom_install_dir>/local_data/app_states
  • <phantom_install_dir>/scm
  • <phantom_install_dir>/vault
  • <phantom_install_dir>/tmp/shared
Last modified on 11 February, 2021
PREVIOUS
Uninstall Splunk Phantom
  NEXT
System requirements for evaluation use

This documentation applies to the following versions of Splunk® Phantom (Legacy): 4.8, 4.9


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters