Notifications
Clear all
Topic starter
12/09/2022 2:35 am
When configuring a Splunk asset for Phantom to connect to a SplunkC loud instance, the user discovers that they need to be able to run two different on_poll searches.
How is this possible
- A . Enter the two queries in the asset as comma separated values.
- B . Configure the second query in the Phantom app for Splunk.
- C . Install a second Splunk app and configure the query in the second app.
- D . Configure a second Splunk asset with the second query.
Suggested Answer: A