Splunk® App for SOAR Export

Use the Splunk App for SOAR Export to Forward Events

Back up and restore configuration files for Splunk App for SOAR Export

On Splunk Enterprise, you can back up and restore the Splunk App for SOAR Export configuration files in case you encounter any problems with the upgrade process overwriting your existing configuration files.

Back up the Splunk App for SOAR Export configuration files

To back up the Splunk App for SOAR Export configuration files, save a copy of the /local directory on your Splunk Enterprise instance. The default location is:

/opt/splunk/etc/apps/phantom/local

Restore the Splunk App for SOAR Export configuration files

Perform the following tasks to restore the Splunk App for SOAR Export configuration files.

  1. Install the latest version of the Splunk App for SOAR Export.
  2. On Splunk Enterprise, move the Splunk App for SOAR Export backup /local configuration files into the current /local directory.
    cp <path of backup>/*.conf /opt/splunk/etc/apps/phantom/local
  3. Restart Splunk.
    /opt/splunk/bin/splunk restart
Last modified on 07 May, 2024
Configure how Splunk SOAR handles multivalue fields in Splunk ES notable events   Troubleshooting and tips for Splunk App for SOAR Export

This documentation applies to the following versions of Splunk® App for SOAR Export: 4.3.13, 4.3.21


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters