Back up and restore configuration files for Splunk App for SOAR Export
On Splunk Enterprise, you can back up and restore the Splunk App for SOAR Export configuration files in case you encounter any problems with the upgrade process overwriting your existing configuration files.
Back up the Splunk App for SOAR Export configuration files
To back up the Splunk App for SOAR Export configuration files, save a copy of the /local
directory on your Splunk Enterprise instance. The default location is:
/opt/splunk/etc/apps/phantom/local
Restore the Splunk App for SOAR Export configuration files
Perform the following tasks to restore the Splunk App for SOAR Export configuration files.
- Install the latest version of the Splunk App for SOAR Export.
- On Splunk Enterprise, move the Splunk App for SOAR Export backup
/local
configuration files into the current/local
directory.cp <path of backup>/*.conf /opt/splunk/etc/apps/phantom/local
- Restart Splunk.
/opt/splunk/bin/splunk restart
Configure how Splunk SOAR handles multivalue fields in Splunk ES notable events | Troubleshooting and tips for Splunk App for SOAR Export |
This documentation applies to the following versions of Splunk® App for SOAR Export: 4.3.13, 4.3.21
Feedback submitted, thanks!