Enable Splunk platform users to use the Splunk Phantom App for Splunk
The Splunk Phantom App for Splunk introduces a new role with new capabilities. These capabilities must be enabled for the Splunk platform user setting up the Splunk Phantom App for Splunk. To add these capabilities to a user, follow these steps:
- Navigate to the Splunk platform instance where you installed the Splunk Phantom App for Splunk.
- Click Settings > Access Controls.
- Click Roles. The
Phantom
role includes Splunk Phantom read and write access, among other capabilities needed to run the Splunk Phantom App for Splunk. - To set up Splunk Phantom capabilites, assign the
Phantom
role to a user or a role. For example, if you want theAdmin
role to always have Splunk Phantom capabilities, click Admin > Inheritance. - Check the box next to Phantom to add the
Phantom
role to theAdmin
role. - Click Save.
Configure the Splunk Phantom App for Splunk | Provide a valid SSL certificate for the connection between Splunk Phantom and Splunk Enterprise |
This documentation applies to the following versions of Splunk® Phantom App for Splunk: 2.7.5
Feedback submitted, thanks!