Splunk® Phantom

Get Started with the Splunk Mobile App for Splunk Phantom

Acrobat logo Download manual as PDF

Splunk Phantom 4.10.7 is the final release of Splunk's Security Orchestration, Automation, and Response (SOAR) system to be called Splunk Phantom. All later versions are named Splunk SOAR (On-premises). For more information, see the Splunk SOAR (On-premises) documentation.
Acrobat logo Download topic as PDF

About the Splunk Mobile App for

The Splunk Mobile App now is available for . You don't have to be in front of a laptop or desktop to take action during an urgent incident. You can use the Splunk Mobile App to view and respond to notifications, view dashboards, view event details, or run a playbook.

To get started with the Splunk Mobile App, perform the following administration and user tasks.

The Splunk Mobile app for Splunk Phantom only works with iOS devices, and does not support multi-tenancy.

Administration tasks

Perform the following administration tasks before using the Splunk Mobile App for :

  1. Open the required ports. See Ports for connecting mobile devices to Phantom using Splunk Connected Experience apps in Install and Upgrade .
  2. Enable the Mobile App registration feature. See Enable or disable registered mobile devices in Administer .
  3. Check the status of ProxyD. See View the health of your system in Administer .

User tasks

To use the app, you must be a registered user in the Phantom platform. Contact your admin about adding new users.

Perform the following tasks after an admin has completed the administration tasks:

  1. Install the app and register your mobile device. See Mobile device registration in Use .
  2. Use the Splunk Mobile App. See Using the Splunk Mobile App for in Use .


You can't use the Splunk Mobile App with two-factor authentication. If you're using two-factor authentication, you see the following error in the WSGI log file: "phantom_ui.ui.shared.HttpError: This user requires two factor authentication. Access to REST API is denied."

Last modified on 07 September, 2021

This documentation applies to the following versions of Splunk® Phantom: 4.8, 4.9, 4.10, 4.10.1, 4.10.2, 4.10.3, 4.10.4, 4.10.6, 4.10.7

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters