ExamGecko
Question list
Search
Search

Question 91 - SPLK-3001 discussion

Report
Export

A set of correlation searches are enabled at a new ES installation, and results are being monitored.

One of the correlation searches is generating many notable events which, when evaluated, are determined to be false positives.

What is a solution for this issue?

A.
Suppress notable events from that correlation search.
Answers
A.
Suppress notable events from that correlation search.
B.
Disable acceleration for the correlation search to reduce storage requirements.
Answers
B.
Disable acceleration for the correlation search to reduce storage requirements.
C.
Modify the correlation schedule and sensitivity for your site.
Answers
C.
Modify the correlation schedule and sensitivity for your site.
D.
Change the correlation search's default status and severity.
Answers
D.
Change the correlation search's default status and severity.
Suggested answer: A
asked 23/09/2024
Felix Bourdier
47 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first