nerdexam
Splunk

SPLK-3001 · Question #1

How should an administrator add a new lookup through the ES app?

The correct answer is D. Upload the lookup file using Configure -> Content Management -> Create New Content ->. https://docs.splunk.com/Documentation/ES/6.1.0/Admin/Createlookups

Lookups and Identity Management

Question

How should an administrator add a new lookup through the ES app?

Options

  • AUpload the lookup file in Settings -> Lookups -> Lookup Definitions
  • BUpload the lookup file in Settings -> Lookups -> Lookup table files
  • CAdd the lookup file to /etc/apps/SplunkEnterpriseSecuritySuite/lookups
  • DUpload the lookup file using Configure -> Content Management -> Create New Content ->

How the community answered

(19 responses)
  • B
    5% (1)
  • C
    5% (1)
  • D
    89% (17)

Explanation

https://docs.splunk.com/Documentation/ES/6.1.0/Admin/Createlookups

Topics

#lookup management#content management#ES configuration#UI navigation

Community Discussion

No community discussion yet for this question.

Full SPLK-3001 Practice