C seems like the right answer. CEF fields are mapped to CIM, and the container is created on the Splunk server. That seems more in line with how the Splunk app would function.
Option A makes the most sense to me. CEF fields are mapped to CIM fields, and a container is created on the SOAR server. That's how I would expect the integration to work.
I think the correct answer is B. CIM fields are mapped to CEF fields and a container is created on the SOAR server. The SOAR app should be handling the translation between the different field formats.
Bernardo
1 months agoTiera
1 months agoCasey
5 days agoFrancine
1 months agoVonda
1 months agoCasie
14 days agoEloisa
15 days agoOwen
19 days agoAlyssa
2 months agoJoana
1 months agoLenna
1 months agoDyan
2 months agoTeresita
2 months agoGeoffrey
2 months agoEura
19 days agoNoe
1 months agoSuzi
1 months agoJusta
1 months agoDyan
2 months ago