Splunk® Phantom App for Splunk

Use the Splunk Phantom App for Splunk to Forward Events

Acrobat logo Download manual as PDF


This documentation does not apply to the most recent version of Splunk® Phantom App for Splunk. For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Create a data model export to send data to Splunk Phantom

To send data to Splunk Phantom in the form of a data model export, follow these steps for guidance.

Before you create a data model export

Before you create a data model export, first set up a data model in your Splunk platform instance. For instructions on setting up a data model in your Splunk platform instance, see the Design data models topic in the Splunk Enterprise Knowledge Manager Manual. Check that your data model has Splunk Phantom read permissions enabled (see Manage data models) so that the Phantom App for Splunk can discover your data models.

Make sure you have set up Splunk Phantom read and write access and configured the Splunk Phantom server. If you haven't already completed this, instructions are found in the Configure the Phantom App for Splunk topic in the Install and Upgrade the Phantom App for Splunk manual.

Create a data model export

To create a data model export in the Phantom App for Splunk, follow these steps:

  1. Navigate to the Event Forwarding tab in the Phantom App for Splunk.
  2. Click New Data Model Export.
  3. Enter a name for the configuration.
  4. Select the data model that contains the data you want to send to Splunk Phantom.
  5. Select an object. Within a data model there are often various datasets, so selecting an object specifies what specific dataset you want to use to send data to Splunk Phantom.
  6. (Optional) Select a container name. You can also leave this field as the auto-generated name.
  7. Select a destination. Choose from the servers that you configured on the Phantom Server Configuration page.
  8. (Optional) Enter a container label. This label must exist in the Splunk Phantom instance. For more information, see Troubleshoot event forwarding.
  9. Create a schedule for the data model export. For the most optimized search, choose the shortest amount of time possible. This is recommended as it helps the system perform better. By default it will be set to Every 5 Minutes.
  10. Select the time frame you want to preview the search results for.
  11. Configure the data model fields. Configuring these fields selects how the data is organized and labeled in Splunk Phantom. The data model fields represent the CIM fields in Splunk, while the CEF fields determine how the data shows up in Splunk Phantom.
    1. Click the plus button of you want to add additional fields to Splunk Phantom. If you choose to add additional fields, ensure to check the Group By box next to the field you want to group your data by in Splunk Phantom.
  12. For custom CEF fields, add a field under Contains if you have actions you want to take on that part of the data. If you configure this field, a drop-down list appears with a list of actions.
  13. Click the Enabled check box to enable or disable your configuration.
  14. Click Save and Preview. If the preview looks correct, click Send to Phantom.
  15. Click Save and Close to save and send your search without previewing it.
  16. If you have configured your data model export correctly, a success message will appear with a link to your container.

Delete or clone your data model export

After you save your data model export, you can choose to delete or clone it by clicking the Delete or Clone buttons under the Actions column. Cloning your data model export can save time later if you choose to create a similar data model export.

Last modified on 13 January, 2021
PREVIOUS
Differences between data models and saved searches
  NEXT
Create a saved search export to send data to Splunk Phantom

This documentation applies to the following versions of Splunk® Phantom App for Splunk: 2.7.5


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters