nerdexam
Splunk

SPLK-2003 · Question #119

When assigning an input parameter to an action while building a playbook, a user notices the artifact value they are looking for does not appear in the auto-populated list. How is it possible to…

The correct answer is A. Type the CEF datapath in manually. When building a playbook in Splunk SOAR, if the desired artifact value does not appear in the auto-populated list of input parameters for an action, users have the option to manually enter the Common Event Format (CEF) datapath for that value. This allows for greater…

Developing Playbooks

Question

When assigning an input parameter to an action while building a playbook, a user notices the artifact value they are looking for does not appear in the auto-populated list. How is it possible to enter the unlisted artifact value?

Options

  • AType the CEF datapath in manually.
  • BDelete and recreate the artifact.
  • CEdit the artifact to enable the List as Parameter option for the CEF value.
  • DEdit the container to allow CEF parameters.

How the community answered

(40 responses)
  • A
    95% (38)
  • B
    3% (1)
  • C
    3% (1)

Explanation

When building a playbook in Splunk SOAR, if the desired artifact value does not appear in the auto-populated list of input parameters for an action, users have the option to manually enter the Common Event Format (CEF) datapath for that value. This allows for greater flexibility and customization in playbook design, ensuring that specific data points can be targeted even if they're not immediately visible in the interface. This manual entry of CEF datapaths allows users to directly reference the necessary data within artifacts, bypassing limitations of the auto-

Topics

#CEF datapath#artifact parameters#action configuration#playbook building

Community Discussion

No community discussion yet for this question.

Full SPLK-2003 Practice