Splunk
SPLK-3001 · Question #76
What role should be assigned to a security team member who will be taking ownership of notable events in the incident review dashboard?
The correct answer is C. ess_analyst. https://docs.splunk.com/Documentation/ES/6.1.0/Install/ConfigureUsersRoles
Investigations and Incident Review
Question
What role should be assigned to a security team member who will be taking ownership of notable events in the incident review dashboard?
Options
- Aess_user
- Bess_admin
- Cess_analyst
- Dess_reviewer
How the community answered
(35 responses)- B3% (1)
- C94% (33)
- D3% (1)
Explanation
https://docs.splunk.com/Documentation/ES/6.1.0/Install/ConfigureUsersRoles
Topics
#ess_analyst#ES roles#incident review#notable events
Community Discussion
No community discussion yet for this question.