nerdexam
Splunk

SPLK-3001 · Question #5

What are the steps to add a new column to the Notable Event table in the Incident Review dashboard?

The correct answer is D. Configure -> Incident Management -> Incident Review Settings -> Table Attributes. https://docs.splunk.com/Documentation/ES/6.1.0/Admin/CustomizeIR Change Incident Review columns You can change the columns displayed on the Incident Review dashboard. Review the existing columns in Incident Review - Table Attributes. Use the action column to edit, remove, or…

Investigations and Incident Review

Question

What are the steps to add a new column to the Notable Event table in the Incident Review dashboard?

Options

  • AConfigure -> Incident Management -> Notable Event Statuses
  • BConfigure -> Content Management -> Type: Correlation Search
  • CConfigure -> Incident Management -> Incident Review Settings -> Event Management
  • DConfigure -> Incident Management -> Incident Review Settings -> Table Attributes

How the community answered

(21 responses)
  • C
    5% (1)
  • D
    95% (20)

Explanation

https://docs.splunk.com/Documentation/ES/6.1.0/Admin/CustomizeIR Change Incident Review columns You can change the columns displayed on the Incident Review dashboard. Review the existing columns in Incident Review - Table Attributes. Use the action column to edit, remove, or change the order of the available columns. Add custom columns by selecting Insert below or selecting More..., then Insert above.

Topics

#incident review#notable events#table attributes#UI configuration

Community Discussion

No community discussion yet for this question.

Full SPLK-3001 Practice