Loading questions...
Updated
What is an example of an ES asset?
Analysts have requested the ability to capture and analyze network traffic data. The administrator has researched the documentation and, based on this research, has decided to integrate the Splunk App for Stream with ES.
Which dashboards will now be supported so analysts can view and analyze network Stream data?
Which setting is used in indexes.conf to specify alternate locations for accelerated storage?
Which of the following is a way to test for a property normalized data model?
Which argument to the | tstats command restricts the search to summarized data only?
When investigating, what is the best way to store a newly-found IOC?
How is it possible to navigate to the list of currently-enabled ES correlation searches?
Which of the following is a risk of using the Auto Deployment feature of Distributed Configuration Management to distribute indexes.conf?
Which of the following are data models used by ES? (Choose all that apply.)
At what point in the ES installation process should Splunk_TA_ForIndexers.spl be deployed to the indexers?
Which correlation search feature is used to throttle the creation of notable events?
Which of the following are examples of sources for events in the endpoint security domain dashboards?
Both Recommended Actions and Adaptive Response Actions use adaptive response. How do they differ?
What does the Security Posture dashboard display?
10.22.63.159, websvr4, and 00:26:08:18: CF:1D would be matched against what in ES?
How should an administrator add a new lookup through the ES app?
Glass tables can display static images and text, the results of ad-hoc searches, and which of the following objects?
Which of the following is a key feature of a glass table?
Create a free account to unlock all questions for this exam.
Log In / Sign UpThe Add-On Builder creates Splunk Apps that start with what?
Which indexes are searched by default for CIM data models?