Exam 6: Splunk IT Service Intelligence Certified Admin

arrow
  • Select Tags
search iconSearch Question
flashcardsStudy Flashcards
  • Select Tags

A site has a single existing search head which hosts a mix of both CIM and non-CIM compliant applications. All of the applications are mission-critical. The customer wants to carefully control cost, but wants good ES performance. What is the best practice for installing ES?

(Multiple Choice)
4.9/5
(36)

Which of the following threat intelligence types can ES download? (Choose all that apply.)

(Multiple Choice)
4.9/5
(40)

The Remote Access panel within the User Activity dashboard is not populating with the most recent hour of data. What data model should be checked for potential errors such as skipped searches?

(Multiple Choice)
4.9/5
(37)

Which of the following is a recommended pre-installation step?

(Multiple Choice)
4.9/5
(37)

What is the maximum recommended volume of indexing per day, per indexer, for a non-cloud (on-prem) ES deployment?

(Multiple Choice)
4.8/5
(30)

Who can delete an investigation?

(Multiple Choice)
4.9/5
(35)

Which component normalizes events?

(Multiple Choice)
4.9/5
(34)

What is the first step when preparing to install ES?

(Multiple Choice)
4.8/5
(31)

When creating custom correlation searches, what format is used to embed field values in the title, description, and drill-down fields of a notable event?

(Multiple Choice)
4.9/5
(34)

How is it possible to navigate to the list of currently-enabled ES correlation searches?

(Multiple Choice)
4.8/5
(40)

An administrator is asked to configure an "Nslookup" adaptive response action, so that it appears as a selectable option in the notable event's action menu when an analyst is working in the Incident Review dashboard. What steps would the administrator take to configure this option?

(Multiple Choice)
4.9/5
(36)

Where is the Add-On Builder available from?

(Multiple Choice)
4.8/5
(36)
Showing 61 - 72 of 72
close modal

Filters

  • Essay(0)
  • Multiple Choice(0)
  • Short Answer(0)
  • True False(0)
  • Matching(0)