Question 1
When creating custom correlation searches, what format is used to embed field values in the title, description, and drill-down fields of a notable event?
When creating custom correlation searches, what format is used to embed field values in the title, description, and drill-down fields of a notable event?
How is it possible to navigate to the list of currently-enabled ES correlation searches?
Which component normalizes events?
How is notable event urgency calculated?
Which of the following would allow an add-on to be automatically imported into Splunk Enterprise Security?
What are the steps to add a new column to the Notable Event table in the Incident Review dashboard?
What is the maximum recommended volume of indexing per day, per indexer, for a non-cloud (on-prem) ES deployment?
An administrator is asked to configure an ''Nslookup'' adaptive response action, so that it appears as a selectable option in the notable event's action menu when an analyst is working in the Incident Review dashboard. What steps would the administrator take to configure this option?
Which of these Is a benefit of data normalization?
Which two fields combine to create the Urgency of a notable event?