Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Splunk SPLK-2003 Exam - Topic 5 Question 86 Discussion

Splunk user account(s) with which roles must be created to configure Phantom with an external Splunk Enterprise instance?
A) superuser, administrator
B) phantomcreate. phantomedit
C) phantomsearch, phantomdelete
D) admin,user

Splunk SPLK-2003 Exam - Topic 5 Question 86 Discussion

Actual exam question for Splunk's SPLK-2003 exam
Question #: 86
Topic #: 5
[All SPLK-2003 Questions]

Splunk user account(s) with which roles must be created to configure Phantom with an external Splunk Enterprise instance?

Show Suggested Answer Hide Answer
Suggested Answer: A

When configuring Splunk Phantom to integrate with an external Splunk Enterprise instance, it is typically required to have user accounts with sufficient privileges to access data and perform necessary actions. The roles of 'superuser' and 'administrator' in Splunk provide the broad set of permissions needed for such integration, enabling comprehensive access to data, management capabilities, and the execution of searches or actions that Phantom may require as part of its automated playbooks or investigations.


Contribute your Thoughts:

0/2000 characters
Isaac
4 days ago
I thought the roles needed were more general, like A) superuser, administrator, but that seems too broad for Phantom integration.
upvoted 0 times
...
Jenelle
9 days ago
I feel like I saw a similar question about user roles in Splunk, but I can't recall the exact answer. Maybe it's C) phantomsearch, phantomdelete?
upvoted 0 times
...
Luke
14 days ago
I think it might be B) phantomcreate, phantomedit, but I'm not entirely sure. I remember something about specific roles for Phantom.
upvoted 0 times
...

Save Cancel