Documentation: https://docs.splunk.com/Documentation/PhantomRemoteSearch
===========================
Version 1.0.17 Release notes
===========================
- Add index phantom_custom_function
- Add endpoint to add Phantom indexes
===========================
Version 1.0.14 Release notes
===========================
- Remove index phantom_docs since Phantom documentation is now hosted on Splunk docs
===========================
Version 1.0.12 Release notes
===========================
- Bug fix remove inputs.conf for Splunk Cloud support
See Phantom Installation Notes documentation for details at https://my.phantom.us/docs/admin/product#SearchSettings
Version 1.0.9 Release notes:
- When using Phantom 4.5 and installing Phantom Remote Search app over a prior v1.0.7 installation, update the existing HTTP Event Collector token to include new index phantom_note on the Splunk server and reindex search data on the Phantom server.
- Newly created phantomdelete user may not be visible on Splunk UI under some circumstances. If so, go to Settings -> Access Controls -> Roles -> phantomdelete and de-select "delete_by_keyword" capability and save. Then, the phantomdelete user will be visible. Once the user is visible, please re-add the "delete_by_keword" capability back to the phantomdelete role.
- Adding the phantomdelete role to a user may produce an error: "Role=phantomdelete is not grantable". To resolve the issue, log into Splunk as admin user and add the delete_by_keyword capability to the admin role. Then, assign the phantomdelete role to a user.
The Phantom Remote Search add-on defines indices and roles used by Phantom when configured to use an external Splunk instance for search data. Install this app if you plan to use this Splunk instance as a remote search node for Phantom.
Installation Notes:
See Phantom documentation for details at https://my.phantom.us/docs/admin/product#SearchSettings
Version 1.0.7 Release notes:
- Newly created phantomdelete user may not be visible on Splunk UI under some circumstances. If so, go to Settings -> Access Controls -> Roles -> phantomdelete and de-select "delete_by_keyword" capability and save. Then, the phantomdelete user will be visible. Once the user is visible, please re-add the "delete_by_keword" capability back to the phantomdelete role.
- Adding the phantomdelete role to a user may produce an error: "Role=phantomdelete is not grantable". To resolve the issue, log into Splunk as admin user and add the delete_by_keyword capability to the admin role. Then, assign the phantomdelete role to a user.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.