nerdexam
Splunk

SPLK-2003 · Question #114

When the Splunk App for SOAR Export executes a Splunk search, which activities are completed?

The correct answer is B. CIM fields are mapped to CEF fields and a container is created on the SOAR server. When the Splunk App for SOAR Export executes a Splunk search, it typically involves mapping Common Information Model (CIM) fields from Splunk to the Common Event Format (CEF) used by SOAR, after which a container is created on the SOAR server to house the related artifacts and…

Ingesting and Handling Data

Question

When the Splunk App for SOAR Export executes a Splunk search, which activities are completed?

Options

  • ACEF fields are mapped to CIM flelds and a container is created on the SOAR server.
  • BCIM fields are mapped to CEF fields and a container is created on the SOAR server.
  • CCEF fields are mapped to CIM and a container is created on the Splunk server.
  • DCIM fields are mapped to CEF and a container is created on the Splunk server.

How the community answered

(32 responses)
  • A
    9% (3)
  • B
    69% (22)
  • C
    3% (1)
  • D
    19% (6)

Explanation

When the Splunk App for SOAR Export executes a Splunk search, it typically involves mapping Common Information Model (CIM) fields from Splunk to the Common Event Format (CEF) used by SOAR, after which a container is created on the SOAR server to house the related artifacts and information. This process allows for the integration of data between Splunk, which uses CIM for data normalization, and Splunk SOAR, which uses CEF as its data format for incidents and Splunk App for SOAR Export is responsible for sending data from your Splunk Enterprise or Splunk Cloud instances to Splunk SOAR. The Splunk App for SOAR Export acts as a translation service between the Splunk platform and Splunk SOAR by performing the following tasks: - Mapping fields from Splunk platform alerts, such as saved searches and data models, to CEF - Translating CIM fields from Splunk Enterprise Security (ES) notable events to CEF fields. - Forwarding events in CEF format to Splunk SOAR, which are stored as artifacts.

Topics

#CIM#CEF#data mapping#container creation

Community Discussion

No community discussion yet for this question.

Full SPLK-2003 Practice