Free SPLK-3001 Exam Braindumps (page: 9)

Page 8 of 22

Adaptive response action history is stored in which index?

  1. cim_modactions
  2. modular_history
  3. cim_adaptiveactions
  4. modular_action_history

Answer(s): A


Reference:

https://docs.splunk.com/Documentation/ES/6.1.0/Install/Indexes



Which of the following actions would not reduce the number of false positives from a correlation search?

  1. Reducing the severity.
  2. Removing throttling fields.
  3. Increasing the throttling window.
  4. Increasing threshold sensitivity.

Answer(s): A



Where is the Add-On Builder available from?

  1. GitHub
  2. SplunkBase
  3. www.splunk.com
  4. The ES installation package

Answer(s): B


Reference:

https://docs.splunk.com/Documentation/AddonBuilder/3.0.1/UserGuide/Installation



Which of the following would allow an add-on to be automatically imported into Splunk Enterprise Security?

  1. A prefix of CIM_
  2. A suffix of .spl
  3. A prefix of TECH_
  4. A prefix of Splunk_TA_

Answer(s): D


Reference:

https://dev.splunk.com/enterprise/docs/developapps/enterprisesecurity/planintegrationes/






Post your Comments and Discuss Splunk® SPLK-3001 exam with other Community members:

SPLK-3001 Discussions & Posts