Backup and restore configuration files for Splunk Phantom App for Splunk
Instructions to backup and restore the Splunk Phantom App for Splunk configuration files.
Backup the Splunk Phantom App for Splunk configuration files
To backup the Splunk Phantom App for Splunk configuration files, save a copy of the /local
directory on your Splunk instance. The default location is:
/opt/splunk/etc/apps/phantom/local
Restore the Splunk Phantom App for Splunk configuration files
Perform the following tasks to restore the Splunk Phantom App for Splunk configuration files.
- Install the latest version of the Splunk Phantom App for Splunk.
- On the Splunk platform, move the Splunk Phantom App for Splunk backup
/local
configuration files into the current/local
directory.cp <path of backup>/*.conf /opt/splunk/etc/apps/phantom/local
- Restart the Splunk platform.
/opt/splunk/bin/splunk restart
Run adaptive response actions in Splunk ES to send notable events to Splunk Phantom | Upgrade the Splunk Phantom App for Splunk |
This documentation applies to the following versions of Splunk® Phantom App for Splunk: 2.7.5, 3.0.5, 4.0.10, 4.0.35
Feedback submitted, thanks!