nerdexam
Splunk

SPLK-2003 · Question #15

Which of the following is a step when configuring event forwarding from Splunk to Phantom?

The correct answer is B. Create a Splunk alert that uses the event_forward.py script to send events to Phantom. A step when configuring event forwarding from Splunk to Phantom is to create a Splunk alert that uses the event_forward.py script to send events to Phantom. This script will convert the Splunk events to CEF format and send them to Phantom as containers. The other options are…

Ingesting and Handling Data

Question

Which of the following is a step when configuring event forwarding from Splunk to Phantom?

Options

  • AMap CIM to CEF fields.
  • BCreate a Splunk alert that uses the event_forward.py script to send events to Phantom.
  • CMap CEF to CIM fields.
  • DCreate a saved search that generates the JSON for the new container on Phantom.

How the community answered

(33 responses)
  • A
    12% (4)
  • B
    79% (26)
  • C
    6% (2)
  • D
    3% (1)

Explanation

A step when configuring event forwarding from Splunk to Phantom is to create a Splunk alert that uses the event_forward.py script to send events to Phantom. This script will convert the Splunk events to CEF format and send them to Phantom as containers. The other options are not valid steps for event forwarding. Configuring event forwarding from Splunk to Phantom typically involves creating a Splunk alert that leverages a script (like event_forward.py) to automatically send triggered event data to Phantom. This setup enables Splunk to act as a detection mechanism that, upon identifying notable events based on predefined criteria, forwards these events to Phantom for further orchestration, automation, and response actions. This integration streamlines the process of incident management by connecting Splunk's powerful data analysis capabilities with Phantom's orchestration and automation framework.

Topics

#event forwarding#Splunk integration#event_forward.py#alert configuration

Community Discussion

No community discussion yet for this question.

Full SPLK-2003 Practice