nerdexam
Splunk

SPLK-2003 · Question #2

Which of the following are the default ports that must be configured on Splunk to allow connections from SOAR?

The correct answer is D. SplunkWeb (8000), SplunkD (8089), HTTP Collector (8088). The default ports that must be configured on Splunk to allow connections from Phantom are SplunkWeb (8000), SplunkD (8089), and HTTP Collector (8088). SplunkWeb is the port used to access the Splunk web interface. SplunkD is the port used to communicate with the Splunk server. HT

Splunk SOAR Environment

Question

Which of the following are the default ports that must be configured on Splunk to allow connections from SOAR?

Options

  • ASplunkWeb (8088), SplunkD (8089), HTTP Collector (8000)
  • BSplunkWeb (8089), SplunkD (8088), HTTP Collector (8000)
  • CSplunkWeb (8421), SplunkD (8061), HTTP Collector (8798)
  • DSplunkWeb (8000), SplunkD (8089), HTTP Collector (8088)

How the community answered

(28 responses)
  • A
    4% (1)
  • C
    4% (1)
  • D
    93% (26)

Explanation

The default ports that must be configured on Splunk to allow connections from Phantom are SplunkWeb (8000), SplunkD (8089), and HTTP Collector (8088). SplunkWeb is the port used to access the Splunk web interface. SplunkD is the port used to communicate with the Splunk server. HTTP Collector is the port used to send data to Splunk using the HTTP Event Collector (HEC). These ports must be configured on Splunk and Phantom to enable the integration between the two products. To allow connections from Splunk Phantom to Splunk, certain default ports need to be open and properly configured. The default ports include SplunkWeb (8000) for web access, SplunkD (8089) for Splunk's management port, and the HTTP Event Collector (HEC) on port 8088, which is used for ingesting data into Splunk. These ports are essential for the communication between Splunk Phantom and Splunk, facilitating data exchange, search capabilities, and the integration of various functionalities between the two platforms.

Topics

#port configuration#Splunk integration#SplunkD#HTTP Collector

Community Discussion

No community discussion yet for this question.

Full SPLK-2003 Practice