nerdexam
Splunk

SPLK-3001 · Question #93

How is it possible to navigate to the list of currently-enabled ES correlation searches?

The correct answer is C. Configure -> Content Management -> Select Type "Correlation" and Status "Enabled". This path allows you to filter and view only the correlation searches that are currently enabled in the Enterprise Security (ES) module.

Correlation Searches and Notable Events

Question

How is it possible to navigate to the list of currently-enabled ES correlation searches?

Options

  • AConfigure -> Correlation Searches -> Select Status "Enabled"
  • BSettings -> Searches, Reports, and Alerts -> Filter by Name of "Correlation"
  • CConfigure -> Content Management -> Select Type "Correlation" and Status "Enabled"
  • DSettings -> Searches, Reports, and Alerts -> Select App of "SplunkEnterpriseSecuritySuite" and

How the community answered

(26 responses)
  • A
    4% (1)
  • B
    8% (2)
  • C
    85% (22)
  • D
    4% (1)

Explanation

This path allows you to filter and view only the correlation searches that are currently enabled in the Enterprise Security (ES) module.

Topics

#correlation searches#Content Management#enabled searches#ES navigation

Community Discussion

No community discussion yet for this question.

Full SPLK-3001 Practice