Welcome to the Splunk Phantom App for Splunk release 4.1.73
This release of the Splunk Phantom App for Splunk includes the following enhancements:
Product Area | Enhancement and Description |
---|---|
Python 3 compatibility | This release of the Splunk Phantom App for Splunk requires Python 3. Check the install stanza in the $SPLUNK_HOME/etc/shclusterapps/phantom/default/app.conf file on the search head cluster and verify that python.version is set to python3 . If there is no setting, or if the setting is python2 , perform the following steps:
The Python version from the $SPLUNK_HOME/etc/shcluster/apps/phantom/local/app.conf file is used to overwrite the value in the $SPLUNK_HOME/etc/apps/phantom/default/app.conf file. |
Performance |
|
Event forwarding |
|
Workbook management | Select multiple workbooks to delete, purge, or restore, and also filter the workbooks that appear in the Workbooks table. See Determine which workbooks are synchronized by deleting, restoring, or purging workbooks. |
App infrastructure changes |
|
Fixed issues in this release
This version of the Splunk Phantom App for Splunk was released on September 16, 2021 and fixes the following issues.
Date resolved | Issue number | Description |
---|---|---|
2021-08-13 | PAPP-16917 | 400 Error When Deleting Very Large Data in Workbooks |
2021-08-13 | PAPP-17218 | Missing backup copy for a duplicate workbook |
Known issues in this release
This version of the Splunk Phantom App for Splunk was released on September 16, 2021 and has the following known issues.
Date filed | Issue number | Description |
---|---|---|
2021-12-22 | PAPP-23255 | Misleading 403 Forbidden error when syncing workbooks with Splunk cloud. Workaround: In the 4.1.73 release of the Phantom App for Splunk, there is an incorrect error message when workbooks are synced. The sync completes successfully, but the error message states that the sync failed. The error message says: There was an error syncing workbooks from Phantom. Status: 403 Text: Forbidden On Splunk: You (user=admin) do not have permission to perform this operation (requires capability: $phantom_read$). You may safely ignore this error message. |
2021-12-01 | PAPP-22054 | Upon successful phantom_retry, some artifacts end up in same container but should be unique. Workaround: NA |
2021-11-26 | PAPP-21689 | Send to SOAR sometime throws "IndexError: list index out of range". |
2021-10-14 | PAPP-20821 | Event forwarding configurations were not being updated to either enabled or disabled. |
2021-10-13 | PAPP-20810 | Events in KV Store phantom_retry only sent if container label is valid. |
2021-08-09 | PAPP-19122 | The SplunkD path is not set correctly in some cases. |
About the Splunk Phantom App for Splunk |
This documentation applies to the following versions of Splunk® Phantom App for Splunk: 4.1.73
Feedback submitted, thanks!