nerdexam
Splunk

SPLK-2003 · Question #74

Which Splunk search command is used to send a notable event to SOAR?

The correct answer is A. sendtophantom. sendtophantom is the correct Splunk search command for forwarding notable events from Splunk Enterprise Security (ES) to Splunk SOAR - the command name reflects SOAR's original product name, "Phantom," before Splunk's acquisition and rebrand. Option B (param.phantom) is not a sea

Ingesting and Handling Data

Question

Which Splunk search command is used to send a notable event to SOAR?

Options

  • Asendtophantom
  • Bparam.phantom
  • Csendevent
  • Dcim_modactions

How the community answered

(17 responses)
  • A
    88% (15)
  • C
    6% (1)
  • D
    6% (1)

Explanation

sendtophantom is the correct Splunk search command for forwarding notable events from Splunk Enterprise Security (ES) to Splunk SOAR - the command name reflects SOAR's original product name, "Phantom," before Splunk's acquisition and rebrand. Option B (param.phantom) is not a search command at all; it resembles a parameter syntax fragment and has no standalone function. Option C (sendevent) does not exist as a standard Splunk command for SOAR integration. Option D (cim_modactions) relates to the Common Information Model's modular action framework - a broader mechanism for triggering actions - not a direct SOAR forwarding command.

Memory tip: The command is literally "send to Phantom" - just remember that Splunk SOAR used to be called Phantom, so the legacy name is baked right into the command: sendtophantom.

Topics

#sendtophantom#notable events#Splunk integration#event ingestion

Community Discussion

No community discussion yet for this question.

Full SPLK-2003 Practice