icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

Thank You

Downloading Phantom Remote Search
SHA256 checksum (phantom-remote-search_1017.tgz) 86165bb5ad13cf6ae69410c2abcee374225a8b80e1152d9d74b4e319b2650ae8 SHA256 checksum (phantom-remote-search_1014.tgz) 34f0e6bf352f5e378d2bfdbbc416dd637c9bbe07a4c211040e558deb8e24fba1 SHA256 checksum (phantom-remote-search_1012.tgz) 710ec3b3de30fde67bf06f7faa74ff6adb6684bf911f2c24a662f711ac7e2423 SHA256 checksum (phantom-remote-search_109.tgz) f2377d0d6b6248c4d7c234abf485d2b5355a424c7b69fed334d15548e4c5d3e8 SHA256 checksum (phantom-remote-search_107.tgz) 74b711d74104cf90563be210fd4499b2d9d3f36b39346c3ca439df89ba34a325
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

splunk

Phantom Remote Search

Splunk Built
This app has been archived. Learn more about app archiving.
This app is NOT supported by Splunk. Please read about what that means for you here.
Overview
Details
This app's functionality has been added to the Splunk App for SOAR (https://splunkbase.splunk.com/app/6361/). We recommend you use that app for this functionality and future updates.

The Phantom Remote Search add-on defines indices and roles used by Phantom when configured to use an external Splunk instance for search data. Install this app if you plan to use this Splunk instance as a remote search node for Phantom.

Release Notes

Version 1.0.17
June 3, 2020

===========================
Version 1.0.17 Release notes
===========================
- Add index phantom_custom_function
- Add endpoint to add Phantom indexes

Version 1.0.14
Jan. 24, 2020

===========================
Version 1.0.14 Release notes
===========================
- Remove index phantom_docs since Phantom documentation is now hosted on Splunk docs

Version 1.0.12
Oct. 30, 2019

===========================
Version 1.0.12 Release notes
===========================
- Bug fix remove inputs.conf for Splunk Cloud support

Version 1.0.9
May 31, 2019

See Phantom Installation Notes documentation for details at https://my.phantom.us/docs/admin/product#SearchSettings

Version 1.0.9 Release notes:
- When using Phantom 4.5 and installing Phantom Remote Search app over a prior v1.0.7 installation, update the existing HTTP Event Collector token to include new index phantom_note on the Splunk server and reindex search data on the Phantom server.
- Newly created phantomdelete user may not be visible on Splunk UI under some circumstances. If so, go to Settings -> Access Controls -> Roles -> phantomdelete and de-select "delete_by_keyword" capability and save. Then, the phantomdelete user will be visible. Once the user is visible, please re-add the "delete_by_keword" capability back to the phantomdelete role.
- Adding the phantomdelete role to a user may produce an error: "Role=phantomdelete is not grantable". To resolve the issue, log into Splunk as admin user and add the delete_by_keyword capability to the admin role. Then, assign the phantomdelete role to a user.

Version 1.0.7
Aug. 29, 2018

The Phantom Remote Search add-on defines indices and roles used by Phantom when configured to use an external Splunk instance for search data. Install this app if you plan to use this Splunk instance as a remote search node for Phantom.

Installation Notes:
See Phantom documentation for details at https://my.phantom.us/docs/admin/product#SearchSettings

Version 1.0.7 Release notes:
- Newly created phantomdelete user may not be visible on Splunk UI under some circumstances. If so, go to Settings -> Access Controls -> Roles -> phantomdelete and de-select "delete_by_keyword" capability and save. Then, the phantomdelete user will be visible. Once the user is visible, please re-add the "delete_by_keword" capability back to the phantomdelete role.
- Adding the phantomdelete role to a user may produce an error: "Role=phantomdelete is not grantable". To resolve the issue, log into Splunk as admin user and add the delete_by_keyword capability to the admin role. Then, assign the phantomdelete role to a user.


Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk LLC in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.