Which of the following is a step when configuring event forwarding from Splunk to Phantom?
Select an option, then click Submit answer.
-
○
Map CIM to CEF fields.
-
○
Create a Splunk alert that uses the event_forward.py script to send events to Phantom.
-
○
Map CEF to CIM fields.
-
○
Create a saved search that generates the JSON for the new container on Phantom.