product
- Why choose Splunk
- Installation record
- price
- Splunk Enterprise Security
- Splunk Phantom (SOAR)
- Splunk ITSI (Next Generation IT Operations)
- Splunk Observability Cloud
- Splunk UBA
- Macnica CSIRT App Basic
- App for Splunk for Financial Institutions
- Splunk Analytics for Hadoop
- About Apps
- Splunk Edge Hub
- What is Splunk
service
- Dashboard/SPL Creation Pack [Implementation/Building Support]
- Version upgrade service [implementation and construction support]
- Smart Security Monitoring App [Original App/Service]
- Splunk × LANSCOPE Original App [Original App/Service]
- Security Monitoring App for Box [Original App/Service]
- Cloud Security Monitoring App [Original App/Service]
- List of services
- Macnica Premium Support for Splunk (utilization support, version upgrade monitoring)
Specifications/Technical Information
Application for evaluation machine
- FAQ

Splunk
Splunk
Splunk Phantom is a SOAR * product that enables efficient and accurate operations by automating tasks in security operations and integrating with other products.
Correlation analysis alerts from installed security devices and SIEM products are used as triggers to automatically execute incident response tasks, accelerating operator decision-making and response.
*SOAR (Security Orchestration and Automated Response) is a new category that achieves operational efficiency through security product integration and task automation.
Challenges in Corporate Security Operations
In recent years, the intensification of cyber attacks has led to increasing issues in organizational security measures, such as operational complexity, rising costs, and a lack of skills and manpower. Splunk Phantom provides the following value to SOCs and CSIRTs, which are facing increasing burdens:

Shortage of human resources

Use the product


Independent and uncoordinated

Time it takes


- Automating repetitive tasks reduces workload and focuses resources
- Automated detection, investigation, and response for faster incident response and reduced time
- Integrating security infrastructure to streamline operations
Splunk Phantom 6 Features
Splunk Phantom helps organizations with their security operations with six features:
1) Automation
インシデント対応手順をプログラム化(Playbook化)、反復的なタスクを自動処理する事で工数を削減します。
Moreover, automated actions are executed within seconds, providing automated intelligence for decision making.
② Orchestration (product integration)
Use APIs provided by other products and tools to obtain information and change settings.
APIs are templated in the form of Apps. Splunk Phantom has over 200 Apps and can execute over 1,000 APIs. In addition, even if there are no existing Apps, you can create new ones with Python code.
Example of integration: Automatically query and obtain IP reputation information from VirusTotal; if malicious, register the IP in the FW blacklist
Example Scenario
③ Collaboration
By centralizing security operations tools in Splunk Phantom and providing a common screen and chat function, it becomes possible for all involved parties to share the history and situation of an incident.
By using Splunk Phantom to carry out consultations and exchanges of opinions between staff members, and even explanations from the SOC department to network administrators, barriers between teams and roles are removed, enabling more efficient operations.
④ Event Management
Manage security events as they occur.
You can efficiently manage events by viewing the occurrence date, status, urgency, etc.
⑤ Case management
Events that qualify as incidents are elevated to cases and managed accordingly.
Cases manage the incident response status, assigned personnel, next response steps, and more, helping to ensure a rapid response without any omissions.
The actions and playbooks set in the template are listed as tasks.
Case Management Page
⑥ Reporting
-
Request information
Request a copy of Splunk Phantom here -
Request a demo
Request a demo of Splunk Phantom

Weekdays: 9:00-17:00
Inquiry/Document request
In charge of Macnica Splunk Co., Ltd.
- TEL:045-476-2010
- E-mail:splunk-sales@macnica.co.jp
Weekdays: 9:00-17:00