When configuring a Splunk asset for Phantom to connect to a SplunkC loud instance, the user discovers that they need to be able to run two different on_poll searches. How is this possible
Wait, I thought Splunk was supposed to be all about simplicity? Now we've got to spin up a whole second asset just to run a couple of searches? This must be what they mean by 'enterprise-grade complexity'.
Wow, two on_poll searches? That's a lot of work. I guess you could try Option A, but that's just going to make everything look like a jumbled mess. Might as well just go with the separate asset approach.
Option B is intriguing, but I have a feeling that's going to lead to some serious headaches down the line. Better to keep the Splunk and Phantom stuff separate, like Option D suggests.
I'm not sure why you'd want to run two different on_poll searches, but if that's what's required, then Option D is the best choice. Trying to cram everything into one asset just seems like a recipe for disaster.
Option D seems like the way to go. You need to configure a second Splunk asset to run the second on_poll search. Keeping things organized and separated is key in these situations.
upvoted 0 times
...
Log in to Pass4Success
Sign in:
Report Comment
Is the comment made by USERNAME spam or abusive?
Commenting
In order to participate in the comments you need to be logged-in.
You can sign-up or
login
Candida
5 months agoKenia
5 months agoJohanna
5 months agoBelen
5 months agoMarget
6 months agoToshia
6 months agoLeota
6 months agoEleonore
6 months agoWillard
6 months agoMona
6 months agoIsadora
6 months agoAyesha
6 months agoDianne
6 months agoYolando
6 months agoLavonda
6 months agoBen
6 months agoOdette
6 months agoEttie
11 months agoWalton
10 months agoOcie
11 months agoAleta
11 months agoDaniel
11 months agoWeldon
11 months agoJoseph
11 months agoGary
11 months agoGayla
12 months agoCarman
10 months agoKeena
10 months agoKayleigh
10 months agoJerlene
11 months agoFiliberto
12 months agoJohnson
12 months agoTheron
1 year agoLajuana
10 months agoRupert
11 months agoMargurite
11 months agoLeota
11 months agoLynelle
1 year agoBeckie
1 year ago