SPLK-2003 · Question #68
Splunk user account(s) with which roles must be created to configure SOAR with an external Splunk Enterprise instance?
The correct answer is A. phantomsearch, phantomdelete. When configuring Splunk SOAR (formerly Phantom) to connect with an external Splunk Enterprise instance, you must create Splunk user accounts assigned the phantomsearch and phantomdelete roles - these are purpose-built roles that grant SOAR the precise permissions it needs to quer
Question
Splunk user account(s) with which roles must be created to configure SOAR with an external Splunk Enterprise instance?
Options
- Aphantomsearch, phantomdelete
- Bphantomcreate, phantomedit
- Csuperuser, administrator
- Dadmin, user
How the community answered
(27 responses)- A93% (25)
- B4% (1)
- D4% (1)
Explanation
When configuring Splunk SOAR (formerly Phantom) to connect with an external Splunk Enterprise instance, you must create Splunk user accounts assigned the phantomsearch and phantomdelete roles - these are purpose-built roles that grant SOAR the precise permissions it needs to query and manage data in Splunk Enterprise without over-privileging the integration.
Why the distractors are wrong:
- B (phantomcreate, phantomedit): These role names don't exist in the required SOAR-Splunk integration setup; SOAR needs search and delete capabilities, not create/edit roles.
- C (superuser, administrator): These are overly broad and not the specific roles Splunk SOAR's integration requires - granting superuser access would violate least-privilege principles and isn't the documented configuration.
- D (admin, user): Generic Splunk built-in roles; they don't provide the tailored permission scope that SOAR needs for its integration workflow.
Memory tip: Think "PhantoSearch + PhantoDelete = PhantomDetect" - SOAR searches Splunk for threats and deletes (cleans up) artifacts, so the two roles mirror exactly what the integration does operationally.
Topics
Community Discussion
No community discussion yet for this question.