Free SPLK-3001 Exam Braindumps

ES apps and add-ons from $SPLUNK_HOME/etc/apps should be copied from the staging instance to what location on the cluster deployer instance?

  1. $SPLUNK_HOME/etc/master-apps/
  2. $SPLUNK_HOME/etc/system/local/
  3. $SPLUNK_HOME/etc/shcluster/apps
  4. $SPLUNK_HOME/var/run/searchpeers/

Answer(s): C

Explanation:

The upgraded contents of the staging instance will be migrated back to the deployer and deployed to the search head cluster members. On the staging instance, copy $SPLUNK_HOME/etc/apps to $SPLUNK_HOME/etc/ shcluster/apps on the deployer. 1. On the deployer, remove any deprecated apps or add-ons in $SPLUNK_HOME/etc/shcluster/apps that were removed during the upgrade on staging. Confirm by reviewing the ES upgrade report generated on staging, or by examining the apps moved into $SPLUNK_HOME/etc/ disabled-apps on staging



How is notable event urgency calculated?

  1. Asset priority and threat weight.
  2. Alert severity found by the correlation search.
  3. Asset or identity risk and severity found by the correlation search.
  4. Severity set by the correlation search and priority assigned to the associated asset or identity.

Answer(s): D


Reference:

https://docs.splunk.com/Documentation/ES/6.1.0/User/Howurgencyisassigned



What kind of value is in the red box in this picture?

  1. A risk score.
  2. A source ranking.
  3. An event priority.
  4. An IP address rating.

Answer(s): C


Reference:

https://docs.splunk.com/Documentation/Splunk/8.0.2/Data/FormateventsforHTTPEventCollector



Where is it possible to export content, such as correlation searches, from ES?

  1. Content exporter
  2. Configure -> Content Management
  3. Export content dashboard
  4. Settings Menu -> ES -> Export

Answer(s): B


Reference:

https://docs.splunk.com/Documentation/ES/6.1.0/Admin/Export






Post your Comments and Discuss Splunk® SPLK-3001 exam with other Community members:

SPLK-3001 Discussions & Posts