Splunk® Phantom App for Splunk

Install and Upgrade the Splunk Phantom App for Splunk

Acrobat logo Download manual as PDF


This documentation does not apply to the most recent version of Splunk® Phantom App for Splunk. For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Enable Splunk platform users to use the Splunk Phantom App for Splunk

The Splunk Phantom App for Splunk introduces a new role with new capabilities. These capabilities must be enabled for the Splunk platform user setting up the Splunk Phantom App for Splunk. To add these capabilities to a user, follow these steps:

  1. Navigate to the Splunk platform instance where you installed the Splunk Phantom App for Splunk.
  2. Click Settings > Access Controls.
  3. Click Roles. The Phantom role includes Splunk Phantom read and write access, among other capabilities needed to run the Splunk Phantom App for Splunk.
  4. To set up Splunk Phantom capabilites, assign the Phantom role to a user or a role. For example, if you want the Admin role to always have Splunk Phantom capabilities, click Admin > Inheritance.
  5. Check the box next to Phantom to add the Phantom role to the Admin role.
  6. Click Save.
Last modified on 13 January, 2021
PREVIOUS
Configure the Splunk Phantom App for Splunk
  NEXT
Provide a valid SSL certificate for the connection between Splunk Phantom and Splunk Enterprise

This documentation applies to the following versions of Splunk® Phantom App for Splunk: 2.7.5


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters