nerdexam
Splunk

SPLK-3001 · Question #5

SPLK-3001 Question #5: Real Exam Question with Answer & Explanation

The correct answer is D. Configure -> Incident Management -> Incident Review Settings -> Table Attributes. https://docs.splunk.com/Documentation/ES/6.1.0/Admin/CustomizeIR Change Incident Review columns You can change the columns displayed on the Incident Review dashboard. Review the existing columns in Incident Review - Table Attributes. Use the action column to edit, remove, or chan

Question

What are the steps to add a new column to the Notable Event table in the Incident Review dashboard?

Options

  • AConfigure -> Incident Management -> Notable Event Statuses
  • BConfigure -> Content Management -> Type: Correlation Search
  • CConfigure -> Incident Management -> Incident Review Settings -> Event Management
  • DConfigure -> Incident Management -> Incident Review Settings -> Table Attributes

Explanation

https://docs.splunk.com/Documentation/ES/6.1.0/Admin/CustomizeIR Change Incident Review columns You can change the columns displayed on the Incident Review dashboard. Review the existing columns in Incident Review - Table Attributes. Use the action column to edit, remove, or change the order of the available columns. Add custom columns by selecting Insert below or selecting More..., then Insert above.

Community Discussion

No community discussion yet for this question.

Full SPLK-3001 Practice
What are the steps to add a new column to the Notable Event table... | SPLK-3001 Q#5 Answer | NerdExam