Splunk® Phantom App for Splunk

Use the Splunk Phantom App for Splunk to Forward Events

Acrobat logo Download manual as PDF


This documentation does not apply to the most recent version of Splunk® Phantom App for Splunk. For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Create a data model export to send data to Splunk Phantom

To send data to Splunk Phantom in the form of a data model export, follow these steps for guidance.

Before you create a data model export

Before you create a data model export, first set up a data model in your Splunk platform instance. For instructions on setting up a data model in your Splunk platform instance, see the Design data models topic in the Splunk Enterprise Knowledge Manager Manual. Check that your data model has Splunk Phantom read permissions enabled (see Manage data models) so that the Phantom App for Splunk can discover your data models.

Make sure you have set up Splunk Phantom read and write access and configured the Splunk Phantom server. If you haven't already completed this, instructions are found in the Configure the Phantom App for Splunk topic in the Install and Upgrade the Phantom App for Splunk manual.

Create a data model export

To create a data model export in the Phantom App for Splunk, follow these steps:

  1. Navigate to the Event Forwarding tab in the Phantom App for Splunk.
  2. Click Add New.
  3. Select Data Model Export.
  4. In the Name field, enter a name for this event forwarding configuration.
  5. From the drop-down list in the Data Model field, select the data model containing the data you want to send to Splunk Phantom. When a data model is selected, the search runs in the background. You can view the results of the data model search after completing the first page of the event forwarding configuration and clicking Next.
  6. From the drop-down list in the Object field, select an object. Within a data model there are often various datasets, so selecting an object specifies the specific dataset you want to use to send data to Splunk Phantom.
  7. In the Select Destination field, choose the Splunk Phantom server where you want to export your data model. Choose from the servers that you configured on the Phantom Server Configuration page. See Connect the Splunk Phantom App for Splunk and the Splunk Platform to a Splunk Phantom server.
  8. (Optional) From the drop-down list in the Container Name field, select a field whose value is used to generate the container name in Splunk Phantom.
    • Select Auto-generate and do not select any Group fields on the next screen to create a container using the name of this forwarding event configuration. For example, if you entered fwconfig in the Name field, the container is created with the name fwconfig.
    • Select Auto-generate and one or more Group fields on the next screen to create a container using the name of this forwarding event configuration and the CEF field name and value for each selected Group field. For example, if you entered fwconfig in the Name field and on the next page select Group using sourceAddress, the container is created with a name such as fwconfig sourceAddress:10.11.12.13.
    • Select a specific CIM field in the Container Name field to create a container using the value of the selected field. For example, if you select the src_ip field which returns the value 10.11.12.13, the container is created with the name 10.11.12.13.
  9. (Optional) Enter a container label in the Container Label field. This label must exist in the Splunk Phantom instance. For more information, see Troubleshoot event forwarding.
  10. Create a schedule for the data model export. For the most optimized search, choose the shortest amount of time possible. This is recommended as it helps the system perform better. By default it will be set to Every 5 Minutes.
  11. Click Next.
  12. (Optional) Click on the name of the data model search to open the search in a new tab. You can use this to validate your search results at any time.
  13. Select the desired severity and sensitivity of the alert sent to Splunk Phantom.
  14. Configure unmapped fields. Select the field you want to map in the Search Fields column and map it to a CEF field in the CEF Fields column. Unmapped fields are ignored and not sent to Splunk Phantom. Click the Group checkbox if you want artifacts with the same value to be grouped together in the same container. For example, if you want group all artifacts with the same value in the _time field, select the Group checkbox next to the _time field and make sure it has a corresponding CEF mapping. Use the drop-down list in the Contains column for additional filtering. For example, select ip in the Contains column for a source field so that only source fields containing an IP address are sent to Splunk Phantom.
  15. (Optional) Click Save Mappings to save your custom mappings as global field mappings. See Configure global field mappings.
  16. Click on Mapped Fields to expand the section and verify the mappings. The Phantom App for Splunk automatically maps fields that it recognizes, or that are part of the global fields mappings. You can edit and of the field mappings as needed.
  17. Click Save and Preview. If the preview looks correct, click Send to Phantom. This will send the individual event from the Splunk platform to Splunk Phantom.
  18. Click Save and Close to save and send your search results.

If you have configured your data model export correctly, a success message will appear with a link to your container.

Delete or clone your data model export

After you save your data model export, you can choose to delete or clone it by clicking the Delete or Clone buttons under the Actions column. Cloning your data model export can save time later if you choose to create a similar data model export.

Last modified on 13 January, 2021
PREVIOUS
Differences between data models and saved searches
  NEXT
Create a saved search export to send data to Splunk Phantom

This documentation applies to the following versions of Splunk® Phantom App for Splunk: 4.0.10, 4.0.35


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters