Splunk® SOAR (On-premises)

Get Started with the Splunk Mobile App for Splunk SOAR (On-premises)

The visual editor for classic playbooks was removed from Splunk SOAR in release 6.4.0. Convert your classic playbooks to modern mode. Your classic playbooks will continue to run and you can view and edit them in the SOAR Python code editor.
For details, see:

About the Splunk Mobile App for

This feature is deprecated.
The Splunk Mobile App for Splunk SOAR (On-premises) is deprecated as of Splunk SOAR (On-premises) version 6.4.0. This feature continues to function and might be be removed in a future version.

See Deprecated feature in the Splunk SOAR (On-premises) version 6.4.0 Release Notes.

The Splunk Mobile App now is available for . You don't have to be in front of a laptop or desktop to take action during an urgent incident. You can use the Splunk Mobile App to view and respond to notifications, view dashboards, view event details, or run a playbook.

To get started with the Splunk Mobile App, perform the following administration and user tasks.

The Splunk Mobile app for Splunk SOAR (On-premises) only works with iOS devices, and does not support multi-tenancy.

Administration tasks

Perform the following administration tasks before using the Splunk Mobile App for :

  1. Open the required ports. See Ports for connecting mobile devices to using Splunk Connected Experience apps in Install and Upgrade .
  2. Enable the Mobile App registration feature. See Enable or disable registered mobile devices in Administer .
  3. Check the status of ProxyD. See View the health of your system in Administer .

User tasks

To use the app, you must be a registered user in the platform. Contact your admin about adding new users.

Perform the following tasks after an admin has completed the administration tasks:

  1. Install the app and register your mobile device. See Mobile device registration in Use .
  2. Use the Splunk Mobile App. See Using the Splunk Mobile App for in Use .

Limitations

You can't use the Splunk Mobile App with two-factor authentication. If you're using two-factor authentication, you see the following error in the WSGI log file: "phantom_ui.ui.shared.HttpError: This user requires two factor authentication. Access to REST API is denied."

Last modified on 04 February, 2025
 

This documentation applies to the following versions of Splunk® SOAR (On-premises): 6.4.0


Please expect delayed responses to documentation feedback while the team migrates content to a new system. We value your input and thank you for your patience as we work to provide you with an improved content experience!

Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters