When configuring a Splunk asset for Phantom to connect to a SplunkC loud instance, the user discovers that they need to be able to run two different on_poll searches. How is this possible
Wait, I thought Splunk was supposed to be all about simplicity? Now we've got to spin up a whole second asset just to run a couple of searches? This must be what they mean by 'enterprise-grade complexity'.
Wow, two on_poll searches? That's a lot of work. I guess you could try Option A, but that's just going to make everything look like a jumbled mess. Might as well just go with the separate asset approach.
Option B is intriguing, but I have a feeling that's going to lead to some serious headaches down the line. Better to keep the Splunk and Phantom stuff separate, like Option D suggests.
I'm not sure why you'd want to run two different on_poll searches, but if that's what's required, then Option D is the best choice. Trying to cram everything into one asset just seems like a recipe for disaster.
Option D seems like the way to go. You need to configure a second Splunk asset to run the second on_poll search. Keeping things organized and separated is key in these situations.
upvoted 0 times
...
Log in to Pass4Success
Sign in:
Report Comment
Is the comment made by USERNAME spam or abusive?
Commenting
In order to participate in the comments you need to be logged-in.
You can sign-up or
login
Ettie
27 days agoOcie
10 days agoAleta
14 days agoDaniel
1 months agoWeldon
9 days agoJoseph
17 days agoGary
27 days agoGayla
1 months agoJerlene
14 days agoFiliberto
2 months agoJohnson
2 months agoTheron
2 months agoLajuana
3 days agoRupert
12 days agoMargurite
25 days agoLeota
1 months agoLynelle
2 months agoBeckie
2 months ago