Where is detailed information about identities stored?
A customer site is experiencing poor performance. The UI response time is high and searches take a very long time to run. Some operations time out and there are errors in the scheduler logs, indicating too many concurrent searches are being started. 6 total correlation searches are scheduled and they have already been tuned to weed out false positives.
Which of the following options is most likely to help performance?
ES needs to be installed on a search head with which of the following options?
The Add-On Builder creates Splunk Apps that start with what?
Accelerated data requires approximately how many times the daily data volume of additional storage space per year?
What tools does the Risk Analysis dashboard provide?
Which of the following features can the Add-on Builder configure in a new add-on?
Which of the following steps will make the Threat Activity dashboard the default landing page in ES?
Which two fields combine to create the Urgency of a notable event?
The Remote Access panel within the User Activity dashboard is not populating with the most recent hour of data. What data model should be checked for potential errors such as skipped searches?
What are adaptive responses triggered by?
At what point in the ES installation process should Splunk_TA_ForIndexes.spl be deployed to the indexers?
After data is ingested, which data management step is essential to ensure raw data can be accelerated by a Data Model and used by ES?
The Brute Force Access Behavior Detected correlation search is enabled, and is generating many false positives. Assuming the input data has already been validated. How can the correlation search be made less sensitive?
Which of these Is a benefit of data normalization?
Following the installation of ES, an admin configured users with the ess_user role the ability to close notable events.
How would the admin restrict these users from being able to change the status of Resolved notable events to Closed?
What does the risk framework add to an object (user, server or other type) to indicate increased risk?
How is it possible to specify an alternate location for accelerated storage?
An administrator is asked to configure an “Nslookup” adaptive response action, so that it appears as a selectable option in the notable event’s action menu when an analyst is working in the Incident Review dashboard. What steps would the administrator take to configure this option?
Which of the following are examples of sources for events in the endpoint security domain dashboards?
After managing source types and extracting fields, which key step comes next In the Add-On Builder?
Which of the following is a way to test for a property normalized data model?
How should an administrator add a new look up through the ES app?
What does the Security Posture dashboard display?
Glass tables can display static images and text, the results of ad-hoc searches, and which of the following objects?
Which of the following lookup types in Enterprise Security contains information about known hostile IP addresses?
Which of the following is a Web Intelligence dashboard?
Which of the following is a risk of using the Auto Deployment feature of Distributed Configuration Management to distribute indexes.conf?
Both “Recommended Actions” and “Adaptive Response Actions” use adaptive response. How do they differ?