What are the steps to add a new column to the Notable Event table in the Incident Review dashboard?
Answer : D
The option to create a Short ID for a notable event is located where?
Answer : B
https://docs.splunk.com/Documentation/ES/6.4.1/User/Takeactiononanotableevent
Where are attachments to investigations stored?
Answer : A
Which of the following is a recommended pre-installation step?
Answer : B
Which argument to the | tstats command restricts the search to summarized data only?
Answer : C
Which setting is used in indexes.conf to specify alternate locations for accelerated storage?
Answer : B
Which of the following is an adaptive action that is configured by default for ES?
Answer : A