Splunk SPLK-3001 - Splunk Enterprise Security Certified Admin Exam
Which lookup table does the Default Account Activity Detected correlation search use to flag known default accounts?
What do threat gen searches produce?
What does the summariesonly=true option do for a correlation search?
When ES content is exported, an app with a .spl extension is automatically created. What is the best practice when exporting and importing updates to ES content?
Following the installation of ES, an admin configured users with the ess_user role the ability to close notable events.
How would the admin restrict these users from being able to change the status of Resolved notable events to Closed?
What tools does the Risk Analysis dashboard provide?
What is the first step when preparing to install ES?
The Add-On Builder creates Splunk Apps that start with what?
Adaptive response action history is stored in which index?