SPLK-2003 · Question #37
What are the differences between cases and events?
The correct answer is C. Cases: contain a collection of containers.. In Splunk SOAR, an event is a security occurrence that may require a response. It is ingested from a third-party source and can be labeled to group related events together. The default label for containers is "Events," which signifies potential threats. A case, on the other hand,
Question
What are the differences between cases and events?
Options
- ACase: potential threats.
- BCases: only include high-level incident artifacts.
- CCases: contain a collection of containers.
- DCases: incidents with a known violation and a plan for correction.
How the community answered
(32 responses)- A3% (1)
- C94% (30)
- D3% (1)
Explanation
In Splunk SOAR, an event is a security occurrence that may require a response. It is ingested from a third-party source and can be labeled to group related events together. The default label for containers is "Events," which signifies potential threats. A case, on the other hand, is a container that holds several containers, consolidating multiple events into one logical management unit. Cases can include artifacts and external evidence such as screen captures, analyst notes, and event data from third-party products. They are used to manage and analyze investigation data tied to specific security events and incidents, providing a structured approach to incident response.
Topics
Community Discussion
No community discussion yet for this question.