Splunk
SPLK-3001 · Question #1
How should an administrator add a new lookup through the ES app?
The correct answer is D. Upload the lookup file using Configure -> Content Management -> Create New Content ->. https://docs.splunk.com/Documentation/ES/6.1.0/Admin/Createlookups
Lookups and Identity Management
Question
How should an administrator add a new lookup through the ES app?
Options
- AUpload the lookup file in Settings -> Lookups -> Lookup Definitions
- BUpload the lookup file in Settings -> Lookups -> Lookup table files
- CAdd the lookup file to /etc/apps/SplunkEnterpriseSecuritySuite/lookups
- DUpload the lookup file using Configure -> Content Management -> Create New Content ->
How the community answered
(19 responses)- B5% (1)
- C5% (1)
- D89% (17)
Explanation
https://docs.splunk.com/Documentation/ES/6.1.0/Admin/Createlookups
Topics
#lookup management#content management#ES configuration#UI navigation
Community Discussion
No community discussion yet for this question.