When configuring a Splunk asset for Phantom to connect to a SplunkC loud instance, the user discovers that they need to be able to run two different on_poll searches. How is this possible
Wait, I thought Splunk was supposed to be all about simplicity? Now we've got to spin up a whole second asset just to run a couple of searches? This must be what they mean by 'enterprise-grade complexity'.
Wow, two on_poll searches? That's a lot of work. I guess you could try Option A, but that's just going to make everything look like a jumbled mess. Might as well just go with the separate asset approach.
Option B is intriguing, but I have a feeling that's going to lead to some serious headaches down the line. Better to keep the Splunk and Phantom stuff separate, like Option D suggests.
I'm not sure why you'd want to run two different on_poll searches, but if that's what's required, then Option D is the best choice. Trying to cram everything into one asset just seems like a recipe for disaster.
Option D seems like the way to go. You need to configure a second Splunk asset to run the second on_poll search. Keeping things organized and separated is key in these situations.
upvoted 0 times
...
Log in to Pass4Success
Sign in:
Report Comment
Is the comment made by USERNAME spam or abusive?
Commenting
In order to participate in the comments you need to be logged-in.
You can sign-up or
login
Candida
3 months agoKenia
3 months agoJohanna
4 months agoBelen
4 months agoMarget
4 months agoToshia
4 months agoLeota
4 months agoEleonore
5 months agoWillard
5 months agoMona
5 months agoIsadora
5 months agoAyesha
5 months agoDianne
5 months agoYolando
5 months agoLavonda
5 months agoBen
5 months agoOdette
5 months agoEttie
10 months agoWalton
9 months agoOcie
9 months agoAleta
9 months agoDaniel
10 months agoWeldon
9 months agoJoseph
9 months agoGary
10 months agoGayla
10 months agoCarman
8 months agoKeena
8 months agoKayleigh
8 months agoJerlene
9 months agoFiliberto
10 months agoJohnson
10 months agoTheron
11 months agoLajuana
9 months agoRupert
9 months agoMargurite
10 months agoLeota
10 months agoLynelle
11 months agoBeckie
11 months ago