Exam Name: | Splunk Enterprise Security Certified Admin Exam | ||
Exam Code: | SPLK-3001 Dumps | ||
Vendor: | Splunk | Certification: | Splunk Enterprise Security Certified Admin |
Questions: | 99 Q&A's | Shared By: | dakota |
Following the Installation of ES, an admin configured Leers with the ©ss_uso r role the ability to close notable events. How would the admin restrict these users from being able to change the status of Resolved notable events to closed?
When creating custom correlation searches, what format is used to embed field values in the title, description, and drill-down fields of a notable event?
Where are attachments to investigations stored?