Splunk® SOAR (On-premises)

Get Started with the Splunk Mobile App for Splunk SOAR (On-premises)

The classic playbook editor will be deprecated in early 2025. Convert your classic playbooks to modern mode.
After the future removal of the classic playbook editor, your existing classic playbooks will continue to run, However, you will no longer be able to visualize or modify existing classic playbooks.
For details, see:

About the Splunk Mobile App for

The Splunk Mobile App now is available for . You don't have to be in front of a laptop or desktop to take action during an urgent incident. You can use the Splunk Mobile App to view and respond to notifications, view dashboards, view event details, or run a playbook.

To get started with the Splunk Mobile App, perform the following administration and user tasks.

The Splunk Mobile app for Splunk SOAR (On-premises) only works with iOS devices, and does not support multi-tenancy.

Administration tasks

Perform the following administration tasks before using the Splunk Mobile App for :

  1. Open the required ports. See Ports for connecting mobile devices to using Splunk Connected Experience apps in Install and Upgrade .
  2. Enable the Mobile App registration feature. See Enable or disable registered mobile devices in Administer .
  3. Check the status of ProxyD. See View the health of your system in Administer .

User tasks

To use the app, you must be a registered user in the platform. Contact your admin about adding new users.

Perform the following tasks after an admin has completed the administration tasks:

  1. Install the app and register your mobile device. See Mobile device registration in Use .
  2. Use the Splunk Mobile App. See Using the Splunk Mobile App for in Use .

Limitations

You can't use the Splunk Mobile App with two-factor authentication. If you're using two-factor authentication, you see the following error in the WSGI log file: "phantom_ui.ui.shared.HttpError: This user requires two factor authentication. Access to REST API is denied."

Last modified on 19 December, 2022
 

This documentation applies to the following versions of Splunk® SOAR (On-premises): 5.1.0, 5.2.1, 5.3.1, 5.3.2, 5.3.3, 5.3.4, 5.3.5, 5.3.6, 5.4.0, 5.5.0, 6.0.0, 6.0.1, 6.0.2, 6.1.0, 6.1.1, 6.2.0, 6.2.1, 6.2.2


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters