How can a user with the username "pat" configure the Analyst Queue to only show new events that are assigned to the current user?
Regarding the Splunk SOAR Automation Broker requirements, which of the following statements is not correct?
When configuring a Splunk asset for SOAR to connect to a Splunk Cloud instance, the user discovers that they need to be able to run two different on_poll searches. How is this possible?
Which of the following is a step when configuring event forwarding from Splunk to Phantom?
Phantom supports multiple user authentication methods such as LDAP and SAML2. What other user authentication method is supported?
What does a user need to do to have a container with an event from Splunk use context-aware actions designed for notable events?
During a second test of a playbook, a user receives an error that states: 'an empty parameters list was passed to phantom.act()." What does this indicate?
When assigning an input parameter to an action while building a playbook, a user notices the artifact value they are looking for does not appear in the auto-populated list.
How is it possible to enter the unlisted artifact value?
Some of the playbooks on the SOAR server should only be executed by members of the admin role. How can this rule be applied?
A user wants to use their Splunk Cloud instance as the external Splunk instance for Phantom. What ports need to be opened on the Splunk Cloud instance to facilitate this? Assume default ports are in use.
Which of the following is the best option for an analyst who wants to run a single action on an event?
A customer wants to design a modular and reusable set of playbooks that all communicate with each other. Which of the following is a best practice for data sharing across playbooks?
Which of the following views provides a holistic view of an incident - providing event metadata, Service Level Agreement status, Severity, sensitivity of an event, and other detailed event info?
Configuring Phantom search to use an external Splunk server provides which of the following benefits?
A user selects the New option under Sources on the menu. What will be displayed?