Steps to connect the Splunk platform with Splunk Phantom or Splunk SOAR
Before you can use the Splunk Phantom App for Splunk, you must establish a connection between the Splunk platform and Splunk Phantom or Splunk SOAR. Perform the following tasks to make the connection:
- If you don't have Splunk Enterprise Security (ES), download and install the Splunk Common Information Model (CIM) app from Splunkbase.
- Enable Splunk platform users to use the Splunk Phantom App for Splunk.
- Provide a valid SSL certificate for the connection between Splunk Phantom and Splunk Enterprise.
- Connect the Splunk Phantom App for Splunk and the Splunk Platform to a Splunk Phantom server or Splunk SOAR.
- (Optional) If you have Splunk Enterprise Security, Run adaptive response actions in Splunk ES to send notable events to Splunk Phantom or Splunk SOAR.
Upgrade the Splunk Phantom App for Splunk on Splunk Cloud Platform | Enable Splunk platform users to use the Splunk Phantom App for Splunk |
This documentation applies to the following versions of Splunk® Phantom App for Splunk: 4.1.73
Feedback submitted, thanks!