Question 29 - SPLK-2003 discussion
Which of the following is a step when configuring event forwarding from Splunk to Phantom?
A.
Map CIM to CEF fields.
B.
Create a Splunk alert that uses the event_forward.py script to send events to Phantom.
C.
Map CEF to CIM fields.
D.
Create a saved search that generates the JSON for the new container on Phantom.
Your answer:
0 comments
Sorted by
Leave a comment first