ExamGecko
Question list
Search
Search

Question 14 - SPLK-2003 discussion

Report
Export

What does a user need to do to have a container with an event from Splunk use context-aware actions designed for notable events?

A.
Include the notable event's event_id field and set the artifacts label to aplunk notable event id.
Answers
A.
Include the notable event's event_id field and set the artifacts label to aplunk notable event id.
B.
Rename the event_id field from the notable event to splunkNotableEventld.
Answers
B.
Rename the event_id field from the notable event to splunkNotableEventld.
C.
Include the event_id field in the search results and add a CEF definition to Phantom for event_id, datatype splunk notable event id.
Answers
C.
Include the event_id field in the search results and add a CEF definition to Phantom for event_id, datatype splunk notable event id.
D.
Add a custom field to the container named event_id and set the custom field's data type to splunk notable event id.
Answers
D.
Add a custom field to the container named event_id and set the custom field's data type to splunk notable event id.
Suggested answer: C

Explanation:

For a container in Splunk SOAR to utilize context-aware actions designed for notable eventsfrom Splunk, it is crucial to ensure that the notable event's unique identifier (event_id) isincluded in the search results pulled into SOAR. Moreover, by adding a Common Event Format(CEF) definition for the event_id field within Phantom, and setting its data type to somethingthat denotes it as a Splunk notable event ID, SOAR can recognize and appropriately handlethese identifiers. This setup facilitates the correct mapping and processing of notable eventdata within SOAR, enabling the execution of context-aware actions that are specifically tailoredto the characteristics of Splunk notable events.

asked 23/09/2024
Sullivan Dabireau
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first