Splunk
  • COVID-19 Response
  • Pricing
  • Training
  • Support
    • Support Portal
    • Support Programs
    • Contact Support
    • Splunk Answers
    • Documentation
    • Product Security Updates
    • Getting Started with Splunk Software
    • Community Support
    • Splunk Services
    • Deutsch
    • Français
    • 日本語
    • 한국어
    • 简体中文
    • 繁體中文
    • Login
    • Sign Up
Splunk
  • IT
  • SECURITY
  • DEVOPS
  • PLATFORM
  • WHY SPLUNK?
  • EXPLORE
    Products | Overview
    CORE
    • Splunk Cloud
    • Splunk Enterprise
    • Splunk Data Stream Processor
    IT OPERATIONS
    • Splunk IT Service Intelligence
    • VictorOps
    • Splunk Insights for AWS Cloud Monitoring
    • Splunk App for Infrastructure
    SECURITY
    • Splunk Enterprise Security
    • Splunk Phantom
    • Splunk User Behavior Analytics
    DEVOPS
    • SignalFx Infrastructure Monitoring
    • SignalFx Microservices APM
    • VictorOps
    Customer Success
    • Customer Case Studies
    • Customer Success
    • Best Practices Guides
    Industries
    • Communications
    • Financial Services
    • Healthcare
    • Public Sector
    • All Industries
    Company
    • About Splunk
    • Partners
    • McLaren Partnership
    • COVID-19 Response
    • Pricing
    • Value Calculator
    • Blogs
    • Free Trials and Downloads
    • Resources
  • Free Splunk
Splunk Free Splunk
Login | Sign Up
IT
SECURITY
DEVOPS
PLATFORM
WHY SPLUNK?
Products
Overview
  • CORE
  • Splunk Cloud
  • Splunk Enterprise
  • Splunk Data Stream Processor
  • IT OPERATIONS
  • Splunk IT Service Intelligence
  • VictorOps
  • Splunk Insights for AWS Cloud Monitoring
  • Splunk App for Infrastructure
  • SECURITY
  • Splunk Enterprise Security
  • Splunk Phantom
  • Splunk User Behavior Analytics
  • DEVOPS
  • SignalFx Infrastructure Monitoring
  • SignalFx Microservices APM
  • VictorOps
Customer Success
  • Customer Case Studies
  • Customer Success
  • Best Practices Guides
Industries
  • Communications
  • Financial Services
  • Healthcare
  • Public Sector
  • All Industries
Company
  • About Splunk
  • Partners
  • McLaren Partnership
COVID-19 Response
Pricing
Value Calculator
Blogs
Free Trials and Downloads
Resources
COVID-19 Response
Pricing
Training
Support
  • Support Portal
  • Support Programs
  • Contact Support
  • Splunk Answers
  • Documentation
  • Product Security Updates
  • Getting Started with Splunk Software
  • Community Support
  • Splunk Services
Languages
  • Deutsch
  • Français
  • 日本語
  • 한국어
  • 简体中文
  • 繁體中文
Contact Sales
Splunk for Security
Splunk for Security
  • Splunk Enterprise Security
  • Splunk Phantom
  • Splunk User Behavior Analytics
  • Pricing
  • More Solutions
    • Splunk Enterprise Security
    • Splunk Phantom
    • Splunk User Behavior Analytics
    • Pricing


Splunk Phantom Security Orchestration & Automation

Harness the full power of your existing security investments with security orchestration, automation and response. With Splunk Phantom, execute actions in seconds not hours.
Free Community Edition
Take a Guided Tour

Phantom stops COVID-19 phishing attacks

Read the Whitepaper

Supercharge your security operations with Splunk Phantom security automation

Work Smarter

Automate repetitive tasks to force multiply your team’s efforts and better focus your attention on mission-critical decisions

Respond Faster

Reduce dwell times with automated investigations. Reduce response times with playbooks that execute at machine speed

Strengthen Your Defenses

Integrate your existing security infrastructure together so that each part is actively participating in your defense strategy

Product Brief
Phantom Overview Video
Product Capabilities
Splunk Phantom combines security infrastructure orchestration, playbook automation and case management capabilities to streamline your team, processes and tools
Orchestrate Security Infrastructure Using Phantom Apps 

Phantom’s flexible app model supports hundreds of tools and thousands of unique APIs, enabling you to connect and coordinate complex workflows across your team and tools. Powerful abstraction allows you to focus on what you want to accomplish, while the platform translates that into tool-specific actions.

Watch Demo Video
Automate Security Actions Using Phantom Playbooks

Phantom enables you to work smarter by executing a series of actions — from detonating files to quarantining devices — across your security infrastructure in seconds, versus hours or more if performed manually. Codify your workflows into automated playbooks using our visual editor (no coding required) or the integrated Python development environment.

Make Your Plays
Collaborate and Respond to Security Incidents Fast

Drive efficient communications across your team with integrated collaboration tools. Use Phantom event and case management to rapidly triage events in an automated, semi-automated or manual fashion. Confirmed events can be aggregated and escalated to cases within Phantom, which enable efficient tracking and monitoring of case status and progress. Measure and report on all security operations activity through to provide human oversight and auditing.

Data, Tools and Teams – All Together
Phantom on Splunk Mobile

Security orchestration, automation and response from your mobile device. Work smarter, respond faster and strengthen your defenses — from anywhere, at anytime. Orchestrate security operations from the palm of your hand. Respond faster than ever because you’re reachable from anywhere. And run playbooks, triage events and collaborate with colleagues on the go.

Phantom on Splunk Mobile Overview
Splunk Phantom Features
Our gears have shifted since Phantom has been implemented. Any new process is always first viewed through the scope of ‘how will we do this with Phantom?’
Jason Mihalow, Senior Cloud Cyber Security Architect
Read the Story
Without using automation and orchestration, I don’t see how companies are going to be able to face the challenges that they have today.
Seth Whitten, VP of integrations and strategic partnerships
Read the Story
Automation with Phantom enables us to process malware email alerts in about 40 seconds vs. 30 minutes or more.
Adam Fletcher, CISO, Blackstone
Read the Story
Previous Next

Analyst Report

Confessions of Security Professionals on Security Orchestration, Automation and Response (SOAR) Tools

Read the Report

E-BOOK

The Essential Guide to Foundational Security Procedures

Read More

WHITE PAPER

Top 10 Essential Capabilities of a Best-of-Breed SOAR

Read More
What can you do with Splunk Phantom?
Contact Sales
Buyer's Guide
PRODUCTS
  • Splunk Cloud
  • Splunk Enterprise
  • Splunk IT Service Intelligence
  • Splunk Insights for AWS Cloud Monitoring
  • Splunk App for Infrastructure
  • VictorOps
  • Splunk Enterprise Security
  • Splunk Phantom
  • Splunk User Behavior Analytics
  • SignalFx Infrastructure Monitoring
  • SignalFx Microservices APM
FREE TRIALS AND DOWNLOADS
PRICING
CALCULATORS
  • Splunk Value Calculator
  • Data Maturity Calculator
  • Critical IT Incident Calculator
SOLUTIONS
  • IT
  • Security
  • DevOps
  • IoT
  • Platform
INDUSTRIES
  • Aerospace and Defense
  • Communications
  • Energy and Utilities
  • Financial Services
  • Healthcare
  • Higher Education
  • Manufacturing
  • Nonprofits
  • Online Services
  • Public Sector
  • Retail
CUSTOMERS
RESOURCES
  • E-books
  • Recorded Webinars
  • Videos
  • White Papers
  • More...
STRATEGY AND BUSINESS INSIGHTS
  • AI Ops
  • Machine Learning
  • Data Insider
  • Data-to-Everything
  • More...
PARTNERS
  • Become a Partner
  • Partner Login
  • More...
SUPPORT
  • Support Portal
  • Contact Support
  • Splunk Services
  • Support Programs
TRAINING
ABOUT SPLUNK
  • Careers
  • Events
  • Investor Relations
  • Leadership Team
  • Locations
  • Newsroom
  • Splunk for Good
  • Splunk Protects
  • Splunk Ventures
  • More...
COVID-19 RESPONSE
CONNECT WITH SPLUNK
  • Support
  • Partners
  • Sales
SPLUNK SITES
  • Splunk Answers
  • Blogs
  • Community
  • .conf
  • Developers
  • Documentation
  • Splunkbase
  • SplunkLive!
  • T-shirt Store
  • User Groups
Splunk
Sitemap | Privacy | Website Terms of Use | Splunk Licensing Terms | Export Control | Modern Slavery Statement | Splunk Patents
© 2005-2020 Splunk Inc. All rights reserved.
Splunk, Splunk>, Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk Inc. in the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners.