Install Splunk Phantom using the Amazon Marketplace Image
Install Splunk Phantom for AWS from the AWS Marketplace in the security category.
Your AWS instance must meet or exceed the requirements for either an evaluation system for evaluation or Proof of Value testing, or a production system for production use, and must include:
- A supported operating system. See Supported operating systems.
- Sufficient storage. See System requirements for production use.
If you need to connect your organization's on-premises infrastructure to an installation of Splunk Phantom hosted in AWS, consult the article Connect Your Data Center to AWS on the AWS web site.
Perform the following tasks to install Splunk Phantom:
- Log in to your AWS EC2 account.
- From your EC2 dashboard, select Launch Instance.
- In the AWS Marketplace, search for Splunk Phantom.
- On the Amazon Machine Image entry, click Select.
- Click Continue.
- Select an instance size. The default is m5.xlarge. Splunk Phantom does not support using instances smaller than t2.xlarge.
- Click Next: Configure Instance Details.
- Configure the instance according to your organization's policies.
- Click Next: Add Storage.
- Add storage.
You can increase disk size later, but you cannot decrease disk size.
- Click Next: Add Tags.
- Add tags to help identify your Splunk Phantom installation in your EC2 dashboard.
- Click Next: Configure Security Group.
- Configure Security Groups. By default, SSH, HTTP, and HTTPS are permitted from all IP addresses. Increase security by limiting access to your organization's IP addresses.
- Click Review and Launch.
- Generate or choose SSH keys.
The SSH username for the Amazon Marketplace Image is centos.
- Click Launch Instances. The installation typically takes 15 minutes to complete.
Next step: log in to verify the installation
You can log in to the Splunk Phantom web interface after the setup script completes to configure user accounts and additional settings. See Log in to the Splunk Phantom web interface.
Splunk Phantom required ports and end points
Install Splunk Phantom as a virtual appliance
This documentation applies to the following versions of Splunk® Phantom (Legacy): 4.8, 4.9