Steps to connect the Splunk platform with Splunk Phantom or Splunk SOAR
Before you can use the Splunk Phantom App for Splunk, you must establish a connection between the Splunk platform and Splunk Phantom or Splunk SOAR. Perform the following tasks to make the connection:
- If you don't have Splunk Enterprise Security (ES), download and install the Splunk Common Information Model (CIM) app from Splunkbase.
- Enable Splunk platform users to use the Splunk Phantom App for Splunk.
- Provide a valid SSL certificate for the connection between Splunk Phantom and Splunk Enterprise.
- Connect the Splunk Phantom App for Splunk and the Splunk Platform to a Splunk Phantom server or Splunk SOAR.
- (Optional) If you have Splunk Enterprise Security, Run adaptive response actions in Splunk ES to send notable events to Splunk Phantom or Splunk SOAR.
Upgrade the Splunk Phantom App for Splunk | Enable Splunk platform users to use the Splunk Phantom App for Splunk |
This documentation applies to the following versions of Splunk® Phantom App for Splunk: 4.1.3
Feedback submitted, thanks!