Which component normalizes events?
When installing Enterprise Security, what should be done after installing the add-ons necessary for normalizing data?
ES apps and add-ons from $SPLUNK_HOME/etc/apps should be copied from the staging instance to what location on the cluster deployer instance?
Which of the following is a key feature of a glass table?
To observe what network services are in use in a network’s activity overall, which of the following dashboards in Enterprise Security will contain the most relevant data?
Which two fields combine to create the Urgency of a notable event?
Which of the following actions can improve overall search performance?
Following the installation of ES, an admin configured users with the ess_user role the ability to close notable events.
How would the admin restrict these users from being able to change the status of Resolved notable events to Closed?
A set of correlation searches are enabled at a new ES installation, and results are being monitored. One of the correlation searches is generating many notable events which, when evaluated, are determined to be false positives.
What is a solution for this issue?
Which of the following is an adaptive action that is configured by default for ES?
An administrator is asked to configure an “Nslookup” adaptive response action, so that it appears as a selectable option in the notable event’s action menu when an analyst is working in the Incident Review dashboard. What steps would the administrator take to configure this option?
A site has a single existing search head which hosts a mix of both CIM and non-CIM compliant applications. All of the applications are mission-critical. The customer wants to carefully control cost, but wants good ES performance. What is the best practice for installing ES?
Where is detailed information about identities stored?
ES needs to be installed on a search head with which of the following options?
Both “Recommended Actions” and “Adaptive Response Actions” use adaptive response. How do they differ?
Where is it possible to export content, such as correlation searches, from ES?
The Remote Access panel within the User Activity dashboard is not populating with the most recent hour of data. What data model should be checked for potential errors such as skipped searches?
Which data model populated the panels on the Risk Analysis dashboard?
The option to create a Short ID for a notable event is located where?
Which setting is used in indexes.conf to specify alternate locations for accelerated storage?
To which of the following should the ES application be uploaded?
What kind of value is in the red box in this picture?
What are the steps to add a new column to the Notable Event table in the Incident Review dashboard?
After installing Enterprise Security, the distributed configuration management tool can be used to create which app to configure indexers?
Which of the following actions would not reduce the number of false positives from a correlation search?
What role should be assigned to a security team member who will be taking ownership of notable events in the incident review dashboard?
Which column in the Asset or Identity list is combined with event security to make a notable event’s urgency?
In order to include an event type in a data model node, what is the next step after extracting the correct fields?
What is an example of an ES asset?