SPLK-5002 Exam Question 36

How can you incorporate additional context into notable events generated by correlation searches?
  • SPLK-5002 Exam Question 37

    One of the goals of a detection engineer is to facilitate the triage process by providing the analyst as much context as possible. One way of accomplishing this is to provide context options through the use of which of the following settings?
  • SPLK-5002 Exam Question 38

    Which of the following macro values will exclude all of the company networks if it is called from the following search?
    index=firewall sourcetype=pan:traffic NOT "company_networks"
  • SPLK-5002 Exam Question 39

    What document can be helpful in understanding the prioritization of risk when comparing entities in an organization?
  • SPLK-5002 Exam Question 40

    Which of the following is not a type of metadata that can be returned by the metadata command?