Hi,
We have recently switched from Phantom to SOAR and I'm trying to send our triggered alerts to SOAR.
I have tested that from Splunk Enterprise to SOAR connect and it works.
But I keep getting the following error for one alert
11-04-2022 05:31:21.724 +1100 WARN sendmodalert [17285 AlertNotifierWorker-0] - action=sendtophantom - Alert action script returned error code=1
11-04-2022 05:31:21.724 +1100 INFO sendmodalert [17285 AlertNotifierWorker-0] - action=sendtophantom - Alert action script completed in duration=1394 ms with exit code=1
I'm also having the same error. How did you fix it?
Did you make it work? What was your issue?
Hi @splunkoptimus,
Our issue was caused by a missing label. So we have label "threat" configured in Phantom but not in SOAR. So SOAR was throwing error due to no matching label found.
Hopefully that helps.
No, there were special characters in my lookup which caused the email alert_action python script to break. Once I removed the special characters email were sent out.