Which of the following features can the Add-on Builder configure in a new add-on?
Answer : B
The Brute Force Access Behavior Detected correlation search is enabled, and is generating many false positives. Assuming the input data has already been validated. How can the correlation search be made less sensitive?
Answer : B
Which of the following would allow an add-on to be automatically imported into Splunk Enterprise Security?
Answer : D
Where are attachments to investigations stored?
Answer : A
Which of these Is a benefit of data normalization?
Answer : A
Which of the following is a key feature of a glass table?
Answer : B
When creating custom correlation searches, what format is used to embed field values in the title, description, and drill-down fields of a notable event?
Answer : A