What metrics can be seen from the System Health Display? (select all that apply)
A user wants to get the playbook results for a single artifact. Which steps will accomplish the?
Why is it good playbook design to create smaller and more focused playbooks? (select all that apply)
Which of the following are the steps required to complete a full backup of a Splunk Phantom deployment' Assume the commands are executed from /opt/phantom/bin and that no other backups have been made.
The SOAR server has been configured to use an external Splunk search head for search and searching on SOAR works; however, the search results don't include content that was being returned by search before configuring external search. Which of the following could be the problem?
To limit the impact of custom code on the VPE, where should the custom code be placed?
Which of the following is a step when configuring event forwarding from Splunk to Phantom?
If no data matches any filter conditions, what is the next block run by the playbook?
A user has written a playbook that calls three other playbooks, one after the other. The user notices that the second playbook starts executing before the first one completes. What is the cause of this behavior?
A user has written a playbook that calls three other playbooks, one after the other. The user notices that the second playbook starts executing before the first one completes. What is the cause of this behavior?
When analyzing events, a working on a case, significant items can be marked as evidence. Where can ail of a case's evidence items be viewed together?
When working with complex data paths, which operator is used to access a sub-element inside another element?
When configuring a Splunk asset for Phantom to connect to a SplunkC loud instance, the user discovers that they need to be able to run two different on_poll searches. How is this possible
Which of the following supported approaches enables Phantom to run on a Windows server?