Question 14 - SPLK-2003 discussion
What does a user need to do to have a container with an event from Splunk use context-aware actions designed for notable events?
A.
Include the notable event's event_id field and set the artifacts label to aplunk notable event id.
B.
Rename the event_id field from the notable event to splunkNotableEventld.
C.
Include the event_id field in the search results and add a CEF definition to Phantom for event_id, datatype splunk notable event id.
D.
Add a custom field to the container named event_id and set the custom field's data type to splunk notable event id.
Your answer:
0 comments
Sorted by
Leave a comment first