Solved

How Should an Administrator Add a New Lookup Through the ES

Question 28

Multiple Choice

How should an administrator add a new lookup through the ES app?


A) Upload the lookup file in Settings -> Lookups -> Lookup Definitions
B) Upload the lookup file in Settings -> Lookups -> Lookup table files
C) Add the lookup file to /etc/apps/SplunkEnterpriseSecuritySuite/lookups Add the lookup file to /etc/apps/SplunkEnterpriseSecuritySuite/lookups
D) Upload the lookup file using Configure -> Content Management -> Create New Content -> Managed Lookup

Correct Answer:

verifed

Verified

Unlock this answer now
Get Access to more Verified Answers free of charge

Related Questions