SPLK-5002 Exam Question 36
How can you incorporate additional context into notable events generated by correlation searches?
SPLK-5002 Exam Question 37
One of the goals of a detection engineer is to facilitate the triage process by providing the analyst as much context as possible. One way of accomplishing this is to provide context options through the use of which of the following settings?
SPLK-5002 Exam Question 38
Which of the following macro values will exclude all of the company networks if it is called from the following search?
index=firewall sourcetype=pan:traffic NOT "company_networks"
index=firewall sourcetype=pan:traffic NOT "company_networks"
SPLK-5002 Exam Question 39
What document can be helpful in understanding the prioritization of risk when comparing entities in an organization?
SPLK-5002 Exam Question 40
Which of the following is not a type of metadata that can be returned by the metadata command?
