Querying data in Splunk for automation workflows in Phantom

This article deals with querying Splunk from within Phantom to enable automation of security use-cases. Often it is required to act upon data within Splunk, or to augment case details in Phantom by querying Splunk for additional information.

Scroll to top