A new project requires event data from SOAR to be sent to an external system via REST. All events with the label notable that are in new status should be sent. Which of the following REST Django expressions will select the correct events?
A.

B.

C.

D.

The correct REST Django expression to retrieve events with the label 'notable' that are in the 'new' status is using the container endpoint, as containers are used to store events and associated data in Splunk SOAR. The expression correctly filters the events by label (_filter_label='notable') and status (_filter_status='new'), ensuring only notable events that are still in the 'new' status are selected.
A and D reference the wrong endpoints (event and notable respectively), which do not align with the container-based model used in Splunk SOAR for storing and filtering events.
B is incorrect due to the use of _filter_name instead of _filter_label, which is not a valid filter in this context.
Splunk SOAR Documentation: REST API Endpoints.
Splunk SOAR Developer Guide: Using Django REST for Filtering.
Stanford
2 months agoTy
2 months agoJamal
3 months agoShoshana
3 months agoNiesha
3 months agoAnnalee
3 months agoMose
4 months agoMicah
4 months agoCorazon
4 months agoIsaac
4 months agoGlory
4 months agoReena
5 months agoGarry
5 months agoCarole
6 months agoTyra
5 months agoAlease
6 months agoMarshall
7 months agoKerry
5 months agoHerminia
5 months agoDominic
6 months agoHui
6 months agoPansy
6 months agoCarisa
7 months agoGail
7 months agoRebecka
7 months agoKristofer
7 months agoIsabelle
5 months agoGail
6 months agoDiane
6 months agoStephane
7 months agoTess
7 months agoRebecka
7 months agoBettina
8 months agoLuz
7 months agoKenneth
7 months agoMarci
7 months agoTess
8 months agoRebecka
8 months ago