ExamGecko
Question list
Search
Search

Question 15 - SPLK-3001 discussion

Report
Export

How is it possible to navigate to the list of currently-enabled ES correlation searches?

A.
Configure -> Correlation Searches -> Select Status “Enabled”
Answers
A.
Configure -> Correlation Searches -> Select Status “Enabled”
B.
Settings -> Searches, Reports, and Alerts -> Filter by Name of “Correlation”
Answers
B.
Settings -> Searches, Reports, and Alerts -> Filter by Name of “Correlation”
C.
Configure -> Content Management -> Select Type “Correlation” and Status “Enabled”
Answers
C.
Configure -> Content Management -> Select Type “Correlation” and Status “Enabled”
D.
Settings -> Searches, Reports, and Alerts -> Select App of “SplunkEnterpriseSecuritySuite” and filter by “- Rule”
Answers
D.
Settings -> Searches, Reports, and Alerts -> Select App of “SplunkEnterpriseSecuritySuite” and filter by “- Rule”
Suggested answer: C

Explanation:

Reference: https://docs.splunk.com/Documentation/ES/6.1.0/Admin/Listcorrelationsearches

asked 23/09/2024
hamza reza
49 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first