SPLK-3001 Exam Question 26
Following the Installation of ES, an admin configured Leers with the ss_uso r role the ability to close notable events. How would the admin restrict these users from being able to change the status of Resolved notable events to closed?
SPLK-3001 Exam Question 27
Which feature contains scenarios that are useful during ES Implementation?
SPLK-3001 Exam Question 28
Which of the following are the default ports that must be configured for Splunk Enterprise Security to function?
SPLK-3001 Exam Question 29
What does the summariesonly=trueoption do for a correlation search?
SPLK-3001 Exam Question 30
How should an administrator add a new lookup through the ES app?
