When configuring a Splunk asset for Phantom to connect to a SplunkC loud instance, the user discovers that they need to be able to run two different on_poll searches. How is this possible
Wait, I thought Splunk was supposed to be all about simplicity? Now we've got to spin up a whole second asset just to run a couple of searches? This must be what they mean by 'enterprise-grade complexity'.
Wow, two on_poll searches? That's a lot of work. I guess you could try Option A, but that's just going to make everything look like a jumbled mess. Might as well just go with the separate asset approach.
Option B is intriguing, but I have a feeling that's going to lead to some serious headaches down the line. Better to keep the Splunk and Phantom stuff separate, like Option D suggests.
I'm not sure why you'd want to run two different on_poll searches, but if that's what's required, then Option D is the best choice. Trying to cram everything into one asset just seems like a recipe for disaster.
Option D seems like the way to go. You need to configure a second Splunk asset to run the second on_poll search. Keeping things organized and separated is key in these situations.
upvoted 0
times
...
Log in to Pass4Success
Sign in:
Report Comment
Is the comment made by USERNAME spam or abusive?
Commenting
In order to participate in the comments you need to be logged-in.
You can sign-up or
login
Candida
6 months agoKenia
6 months agoJohanna
7 months agoBelen
7 months agoMarget
7 months agoToshia
7 months agoLeota
7 months agoEleonore
8 months agoWillard
8 months agoMona
8 months agoIsadora
8 months agoAyesha
8 months agoDianne
8 months agoYolando
8 months agoLavonda
8 months agoBen
8 months agoOdette
8 months agoEttie
1 year agoWalton
12 months agoOcie
1 year agoAleta
1 year agoDaniel
1 year agoWeldon
1 year agoJoseph
1 year agoGary
1 year agoGayla
1 year agoCarman
11 months agoKeena
11 months agoKayleigh
11 months agoJerlene
1 year agoFiliberto
1 year agoJohnson
1 year agoTheron
1 year agoLajuana
12 months agoRupert
1 year agoMargurite
1 year agoLeota
1 year agoLynelle
1 year agoBeckie
1 year ago