ExamGecko
Question list
Search
Search

Question 95 - SPLK-3001 discussion

Report
Export

What does the summariesonly=true option do for a correlation search?

A.
Searches only accelerated data.
Answers
A.
Searches only accelerated data.
B.
Forwards summary indexes to the indexing tier.
Answers
B.
Forwards summary indexes to the indexing tier.
C.
Uses a default summary time range.
Answers
C.
Uses a default summary time range.
D.
Searches summary indexes only.
Answers
D.
Searches summary indexes only.
Suggested answer: A

Explanation:

Reference: https://community.splunk.com/t5/Splunk-Enterprise-Security/Why-do-correlationsearches-in- Enterprise-Security-not-use-quot/m-p/262622

asked 23/09/2024
PEDRO ARIAS
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first