SPLK-2003 · Question #74
Which Splunk search command is used to send a notable event to SOAR?
The correct answer is A. sendtophantom. sendtophantom is the correct Splunk search command for forwarding notable events from Splunk Enterprise Security (ES) to Splunk SOAR - the command name reflects SOAR's original product name, "Phantom," before Splunk's acquisition and rebrand. Option B (param.phantom) is not a sea
Question
Which Splunk search command is used to send a notable event to SOAR?
Options
- Asendtophantom
- Bparam.phantom
- Csendevent
- Dcim_modactions
How the community answered
(17 responses)- A88% (15)
- C6% (1)
- D6% (1)
Explanation
sendtophantom is the correct Splunk search command for forwarding notable events from Splunk Enterprise Security (ES) to Splunk SOAR - the command name reflects SOAR's original product name, "Phantom," before Splunk's acquisition and rebrand. Option B (param.phantom) is not a search command at all; it resembles a parameter syntax fragment and has no standalone function. Option C (sendevent) does not exist as a standard Splunk command for SOAR integration. Option D (cim_modactions) relates to the Common Information Model's modular action framework - a broader mechanism for triggering actions - not a direct SOAR forwarding command.
Memory tip: The command is literally "send to Phantom" - just remember that Splunk SOAR used to be called Phantom, so the legacy name is baked right into the command: sendtophantom.
Topics
Community Discussion
No community discussion yet for this question.