Splunk® SOAR (Cloud)

Administer Splunk SOAR (Cloud)

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

Configure search in

uses an embedded, preconfigured version of Splunk Enterprise as its native search engine. Your organization might want to use a different Splunk Enterprise deployment with or use an external Elasticsearch instance.

Configure to use an external Splunk Enterprise or Splunk Cloud instance for search

This table summarizes the available options for configuring a Splunk Enterprise or Splunk Cloud instance for search in .

Search Option Description
Embedded Splunk Enterprise Instance This is the default. No additional configuration is required.
External Standalone Splunk Enterprise Instance Use this option to connect your instance to a single, external instance of Splunk Enterprise or Splunk Cloud.


This option requires the Splunk Phantom Remote Search app.

  1. See Check prerequisites for Splunk App for SOAR in the Install and Configure Splunk App for SOAR manual to verify version compatibility and requirements.
  2. See Set up remote search on a standalone Splunk Cloud Platform or Splunk Enterprise instance in the Install and Configure Splunk App for SOAR manual for instructions.
External Distributed Splunk Enterprise Instance Use this option to connect your instance to a Splunk Enterprise or Splunk Cloud deployment that contains one or more search heads, or one or more indexers.


This option requires the Splunk Phantom Remote Search app.

  1. See Check prerequisites for Splunk App for SOAR in the Install and Configure Splunk App for SOAR manual to verify version compatibility and requirements.
  2. See Set up remote search on a distributed Splunk Cloud Platform or Splunk Enterprise instance in the Install and Configure Splunk App for SOAR manual for instructions.

Integrating with Splunk Cloud requires the following additional information and actions:

  • You must use a public certificate from a verified or trusted certificate authority (CA).
  • You must contact Splunk Customer Support for assistance with Splunk Cloud integration. You will need to provide the path to your certificate and your CA.
  • You must enable certificate verification on your assets.

Reindex data to make newly added information searchable

There are some situations where data coming in to can't be indexed, and therefore can't be searched. You can reindex information sections to make this information searchable. See Reindex data to make newly added information searchable in the Splunk Phantom Remote Search manual.

Last modified on 17 May, 2023
PREVIOUS
Customize email templates in
  NEXT
Configure Google Maps for visual geolocation data

This documentation applies to the following versions of Splunk® SOAR (Cloud): current


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters