Splunk® Phantom (Legacy)

Administer Splunk Phantom

Splunk Phantom 4.10.7 is the final release of Splunk's Security Orchestration, Automation, and Response (SOAR) system to be called Splunk Phantom. All later versions are named Splunk SOAR (On-premises). For more information, see the Splunk SOAR (On-premises) documentation.

View the action run history

You can view the history of actions run on your Splunk Phantom instance.

  1. From the Main Menu, select Administration.
  2. Select System Health > Action Run History.

The Action Run History page displays a sortable list of action runs. Each column except for View Results is sortable. The table displays the following columns:

Column name Description
Name The name of the action that was run.
Run ID The numeric ID of the action that was run.
Event ID The numeric ID of the event the action was run against.
Start Time The time the action started.
End Time The time the action finished.
Status Whether the action succeeded or failed.
Prompted If the action taken was a prompt or manual task action, the ID of the user assigned the action appears here.
Run By The name of the user who ran the action.
View Results A hyperlink to the action results in Investigation. For prompt or manual task actions, the link opens a window containing the prompt or task results.
Last modified on 25 January, 2020
View the playbook run history in Splunk Phantom   Use ITSI to monitor the health of your deployment

This documentation applies to the following versions of Splunk® Phantom (Legacy): 4.8, 4.9, 4.10, 4.10.1, 4.10.2, 4.10.3, 4.10.4, 4.10.6, 4.10.7


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters