SPLK-3001 · Question #49
Which of the following is part of tuning correlation searches for a new ES installation?
The correct answer is B. Configuring correlation adaptive responses. Configuring adaptive responses (B) is a core tuning step for correlation searches in Splunk Enterprise Security (ES). Adaptive responses define the actions a correlation search takes when it fires - such as creating notable events, assigning risk scores, or triggering scripts…
Question
Which of the following is part of tuning correlation searches for a new ES installation?
Options
- AConfiguring correlation permissions.
- BConfiguring correlation adaptive responses.
- CConfiguring correlation notable event index.
- DConfiguring correlation result storage.
How the community answered
(54 responses)- A4% (2)
- B80% (43)
- C11% (6)
- D6% (3)
Explanation
Configuring adaptive responses (B) is a core tuning step for correlation searches in Splunk Enterprise Security (ES). Adaptive responses define the actions a correlation search takes when it fires - such as creating notable events, assigning risk scores, or triggering scripts - and tuning these responses is essential to making a new ES deployment operationally useful.
- A is wrong because correlation permissions are an administrative/access-control concern, not a tuning activity for the searches themselves.
- C is wrong because the notable event index (
notable) is a pre-built ES data model destination set up during installation, not something you configure per correlation search during tuning. - D is wrong because "correlation result storage" is not a distinct ES configuration concept - it's a plausible-sounding distractor with no specific meaning in the ES tuning workflow.
Memory tip: Think "A = Action." Adaptive responses are the actions your correlation searches perform. When you tune a search, you're deciding what it should do when it fires - that's configuring its Adaptive responses.
Topics
Community Discussion
No community discussion yet for this question.