SPLK-3001 無料問題集「Splunk Enterprise Security Certified Admin」
A customer site is experiencing poor performance. The UI response time is high and searches take a very long time to run. Some operations time out and there are errors in the scheduler logs, indicating too many concurrent searches are being started. 6 total correlation searches are scheduled and they have already been tuned to weed out false positives.
Which of the following options is most likely to help performance?
Which of the following options is most likely to help performance?
正解:B
解答を投票する
A set of correlation searches are enabled at a new ES installation, and results are being monitored. One of the correlation searches is generating many notable events which, when evaluated, are determined to be false positives.
What is a solution for this issue?
What is a solution for this issue?
正解:B
解答を投票する
解説: (JPNTest メンバーにのみ表示されます)
An administrator is asked to configure an "Nslookup" adaptive response action, so that it appears as a selectable option in the notable event's action menu when an analyst is working in the Incident Review dashboard. What steps would the administrator take to configure this option?
正解:D
解答を投票する
解説: (JPNTest メンバーにのみ表示されます)