Splunk® AR for iOS

Administer Splunk AR

Acrobat logo Download manual as PDF

This documentation does not apply to the most recent version of AR. Click here for the latest version.
Acrobat logo Download topic as PDF

Add Phantom playbooks to AR workspaces in Splunk AR (beta)

Workflow Automation is a beta feature available in Splunk AR version 2.1.0 and later. Workflow Automation integrates Phantom playbooks into AR workspaces to guide users through real-world tasks. To use Workflow Automation, create playbooks in Phantom and then add them to your AR workspaces in the Splunk AR mobile app.

Make sure you're registered to a Splunk instance, enable the Workflow Automation feature, and register to a Phantom instance. Then you can add playbooks to your workspaces to guide Splunk AR users through real life tasks.

Keep in mind that Workflow Automation is a beta feature that might have undocumented issues. If you run into issues, have questions, or need help with the Workflow Automation feature, email sammyl@splunk.com.

Enable Workflow Automation

After users register their devices to a Splunk instance, they must complete the following steps on their mobile device and in Splunk Phantom to enable Workflow Automation.


Before using Workflow Automation in Splunk AR, complete the following tasks:

  1. Set up Splunk AR and AR workspaces. See Set up Splunk AR in the Get started with Splunk AR topic.
  2. Install Splunk Phantom. See Get Splunk Phantom for more information about installing Splunk Phantom.
  3. Make sure users who are using Workflow Automation have registered their devices to a Splunk instance. See Register your device in Use Splunk Cloud Gateway to register to a Splunk instance.
  4. Make sure you and your Splunk AR users have the right permissions. See Manage roles and permissions in Splunk to learn about Splunk Phantom permissions and see Configure Splunk AR permissions to learn about about playbook permissions in Splunk AR.

Mobile device steps

  1. Type https://spl.mobi/ar/feature/enable_phantom into a text editor or send it to your mobile device.
  2. Tap https://spl.mobi/ar/feature/enable_phantom on your mobile device. This takes you to the Splunk AR Settings.
  3. Tap Splunk Apps.
  4. Tap the Phantom switch to enable Workflow Automation. You get a registration code. Use this code to register to a Splunk Phantom instance.

If you run into issues, see Troubleshoot enabling Workflow Automation.


Splunk Phantom steps

In your Phantom instance, navigate to Admin > Account Settings > Mobile Device Registration > + New Device. Register to a Splunk Phantom instance using the code from your mobile device.


You can disable the Workflow Automation feature by navigating to https://spl.mobi/ar/feature/disable_phantom on your mobile device.

Create playbooks in Splunk Phantom for Splunk AR

Create a playbook in Splunk Phantom to add to AR workspaces in the Splunk AR mobile app.

See Create a playbook in Splunk Phantom to use in the Splunk AR Workflow Automation feature for a simple use case and how to create a basic playbook for Workflow Automation.

See Phantom playbook API tutorial overview and Tutorial: Create a simple playbook in Splunk Phantom to learn how to create playbooks.

Add a playbook to a workspace in the Splunk AR mobile app

Here's how to add a playbook to an AR workspace in the Splunk AR app.



  1. In the Splunk AR app, scan an asset tag to open a workspace.
  2. Make sure the workspace is selected.
  3. Tap the book button.
  4. Select a playbook to add to your workspace.
  5. Name the playbook.
  6. Adjust the playbook like how you would adjust a visualization or note.
  7. Tap save.

Splunk AR users can now play the playbook and go through its prompts. See Run a Splunk Phantom playbook in Splunk AR for user instructions on how to run a playbook in Splunk AR.

Last modified on 05 May, 2020
Save Splunk AR workspace orientation with NFC tags
Workflow Automation Security

This documentation applies to the following versions of Splunk® AR for iOS: 2.1.0, 2.2.0

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters