nerdexam
Splunk

SPLK-3001 · Question #32

The Brute Force Access Behavior Detected correlation search is enabled, and is generating many false positives. Assuming the input data has already been validated. How can the correlation search be…

The correct answer is B. Edit the search, look for where or xswhere statements, and after the threshold value being. https://docs.splunk.com/Documentation/ES/6.1.0/User/Howurgencyisassigned

Tuning Correlation Searches

Question

The Brute Force Access Behavior Detected correlation search is enabled, and is generating many false positives. Assuming the input data has already been validated. How can the correlation search be made less sensitive?

Options

  • AEdit the search and modify the notable event status field to make the notable events less urgent.
  • BEdit the search, look for where or xswhere statements, and after the threshold value being
  • CEdit the search, look for where or xswhere statements, and alter the threshold value being
  • DModify the urgency table for this correlation search and add a new severity level to make notable

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    68% (19)
  • C
    21% (6)
  • D
    7% (2)

Explanation

https://docs.splunk.com/Documentation/ES/6.1.0/User/Howurgencyisassigned

Topics

#false positives#threshold tuning#brute force detection#correlation search editing

Community Discussion

No community discussion yet for this question.

Full SPLK-3001 Practice