Install: TruSTAR for Splunk Phantom Cyber
This document explains how to install the TruSTAR Workflow App for Splunk Phantom Cyber. You can use this App to set up Phantom Cyber orchestration playbooks that utilize the context of TruSTAR’s Intelligence Reports and Indicators.
- Splunk Phantom Cyber platform
Installing the App
The certified TruSTAR Workflow App is available for direct download through the Phantom app store. TruSTAR recommends this process rather than manually installing it.
If you cannot download the app from the Phantom app store, you can manually install it using directions in the TruSTAR for Phantom FAQ.
Configuring the App
- Enter the required information in the Asset Info tab.
- Click the Asset Settings tab and enter the following information:
- URL: https://api.trustar.co
- OAuth client ID and secret key- Your TruSTAR API credentials (Finding your API Keys)
- Enclave IDs: All the enclave IDs that you would like to either submit reports to or search through when using the Workflow App (Finding Enclave IDs)
- Click the TEST CONNECTIVITY button. If the test fails, recheck your credentials. If the test still fails, contact email@example.com for assistance.
- Click the SAVE button to save configuration details.
- Click the Ingest Settings tab.
- Change any settings, as required for your environment.
- Click SAVE to save any changes you made.