C seems like the right answer. CEF fields are mapped to CIM, and the container is created on the Splunk server. That seems more in line with how the Splunk app would function.
Option A makes the most sense to me. CEF fields are mapped to CIM fields, and a container is created on the SOAR server. That's how I would expect the integration to work.
I think the correct answer is B. CIM fields are mapped to CEF fields and a container is created on the SOAR server. The SOAR app should be handling the translation between the different field formats.
Bernardo
16 days agoTiera
17 days agoFrancine
19 days agoVonda
20 days agoOwen
4 days agoAlyssa
2 months agoJoana
21 days agoLenna
29 days agoDyan
2 months agoTeresita
2 months agoGeoffrey
2 months agoEura
4 days agoNoe
20 days agoSuzi
23 days agoJusta
24 days agoDyan
2 months ago