Splunk user account(s) with which roles must be created to configure Phantom with an external Splunk Enterprise instance?
When configuring Splunk Phantom to integrate with an external Splunk Enterprise instance, it is typically required to have user accounts with sufficient privileges to access data and perform necessary actions. The roles of 'superuser' and 'administrator' in Splunk provide the broad set of permissions needed for such integration, enabling comprehensive access to data, management capabilities, and the execution of searches or actions that Phantom may require as part of its automated playbooks or investigations.
Isaac
4 days agoJenelle
9 days agoLuke
14 days ago