Splunk® Phantom App for Splunk

Use the Splunk Phantom App for Splunk to Forward Events

This documentation does not apply to the most recent version of Splunk® Phantom App for Splunk. For documentation on the most recent version, go to the latest release.

Welcome to the Splunk Phantom App for Splunk release 4.1.3

This release of the Splunk Phantom App for Splunk includes the following enhancements:

  • This release of the Splunk Phantom App for Splunk connects both Splunk Phantom and Splunk SOAR to your Splunk platform.
  • Use the Splunk Phantom App for Splunk to synchronize workbooks across multiple Splunk Phantom instances or Splunk SOAR. See Synchronize workbooks across multiple Splunk Phantom servers.
  • Splunk Enterprise Security (ES) is no longer required to integrate Splunk Phantom and Splunk SOAR with the Splunk platform. If you want to use adaptive response actions or AR relay without Splunk ES, you must download and install the Splunk Common Information Model (CIM) app from Splunkbase.
  • Alert Action Configurations tab is moved to the Configurations tab and no longer uses JQuery.
  • Splunk platform events not created in Splunk Phantom are stored in KV Store. Attempts are made every 60 seconds to send these events to Splunk Phantom until the events are successfully sent.

Fixed issues in this release

This version of the Splunk Phantom App for Splunk was released on May 27, 2021 and fixes the following issues.

Date resolved Issue number Description
2021-05-25 PAPP-14419 Phantom App for Splunk- forwarding savedsearch report is hanging with 0 results

Known issues in this release

This version of the Splunk Phantom App for Splunk has the following issues and workarounds.



Date filed Issue number Description
2021-05-25 PAPP-17218 Missing backup copy for a duplicate workbook
2021-05-07 PAPP-16917 400 Error When Deleting Very Large Data in Workbooks
Last modified on 25 June, 2021
  About the Splunk Phantom App for Splunk

This documentation applies to the following versions of Splunk® Phantom App for Splunk: 4.1.3


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters