Analysts have requested the ability to capture and analyze network traffic data. The administrator has researched the documentation and, based on this research, has decided to integrate the Splunk App for Stream with ES.
Which dashboards will now be supported so analysts can view and analyze network Stream data?
What role should be assigned to a security team member who will be taking ownership of notable events in the incident review dashboard?
When creating custom correlation searches, what format is used to embed field values in the title, description, and drill-down fields of a notable event?
What does the risk framework add to an object (user, server or other type) to indicate increased risk?
After data is ingested, which data management step is essential to ensure raw data can be accelerated by a Data Model and used by ES?
Which of the following would allow an add-on to be automatically imported into Splunk Enterprise Security?
Which of the following steps will make the Threat Activity dashboard the default landing page in ES?
A customer site is experiencing poor performance. The UI response time is high and searches take a very long time to run. Some operations time out and there are errors in the scheduler logs, indicating too many concurrent searches are being started. 6 total correlation searches are scheduled and they have already been tuned to weed out false positives.
Which of the following options is most likely to help performance?
After managing source types and extracting fields, which key step comes next In the Add-On Builder?
Which of the following threat intelligence types can ES download? (Choose all that apply)
Following the installation of ES, an admin configured users with the ess_user role the ability to close notable events.
How would the admin restrict these users from being able to change the status of Resolved notable events to Closed?
Which of the following is an adaptive action that is configured by default for ES?
A newly built custom dashboard needs to be available to a team of security analysts In ES. How is It possible to Integrate the new dashboard?
Which setting is used in indexes.conf to specify alternate locations for accelerated storage?
Following the Installation of ES, an admin configured Leers with the ©ss_uso r role the ability to close notable events. How would the admin restrict these users from being able to change the status of Resolved notable events to closed?