Exam (elaborations)
Splunk Administering Enterprise Security 5.3 questions with correct answers
- Course
- Institution
Indexes CORRECT ANSWER notable = notable events created by correlation searches gia_summary = for Sec Intel > User Intel > Access Anomalies dashboard, filled by "Access - Geographically Improbable Access - Summary Gen" threat_activity = threat gen search matches(every 5 min) Roles CO...
[Show more]