ExamGecko
Question list
Search
Search

Question 23 - SPLK-3001 discussion

Report
Export

How should an administrator add a new lookup through the ES app?

A.
Upload the lookup file in Settings -> Lookups -> Lookup Definitions
Answers
A.
Upload the lookup file in Settings -> Lookups -> Lookup Definitions
B.
Upload the lookup file in Settings -> Lookups -> Lookup table files
Answers
B.
Upload the lookup file in Settings -> Lookups -> Lookup table files
C.
Add the lookup file to /etc/apps/SplunkEnterpriseSecuritySuite/lookups
Answers
C.
Add the lookup file to /etc/apps/SplunkEnterpriseSecuritySuite/lookups
D.
Upload the lookup file using Configure -> Content Management -> Create New Content -> Managed Lookup
Answers
D.
Upload the lookup file using Configure -> Content Management -> Create New Content -> Managed Lookup
Suggested answer: D

Explanation:

Reference: https://docs.splunk.com/Documentation/ES/6.1.0/Admin/Createlookups

asked 23/09/2024
Matt Harrold
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first