Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Splunk Exam SPLK-2003 Topic 1 Question 28 Discussion

Actual exam question for Splunk's SPLK-2003 exam
Question #: 28
Topic #: 1
[All SPLK-2003 Questions]

When configuring a Splunk asset for Phantom to connect to a SplunkC loud instance, the user discovers that they need to be able to run two different on_poll searches. How is this possible

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

Filiberto
2 days ago
I think option D) Configure a second Splunk asset with the second query makes more sense, as it keeps things separate and organized.
upvoted 0 times
...
Johnson
4 days ago
I disagree, I believe the correct answer is B) Configure the second query in the Phantom app for Splunk.
upvoted 0 times
...
Theron
8 days ago
I'm not sure why you'd want to run two different on_poll searches, but if that's what's required, then Option D is the best choice. Trying to cram everything into one asset just seems like a recipe for disaster.
upvoted 0 times
...
Lynelle
8 days ago
I think the answer is A) Enter the two queries in the asset as comma separated values.
upvoted 0 times
...
Beckie
9 days ago
Option D seems like the way to go. You need to configure a second Splunk asset to run the second on_poll search. Keeping things organized and separated is key in these situations.
upvoted 0 times
...

Save Cancel