Splunk
SPLK-3001 · Question #93
How is it possible to navigate to the list of currently-enabled ES correlation searches?
The correct answer is C. Configure -> Content Management -> Select Type "Correlation" and Status "Enabled". This path allows you to filter and view only the correlation searches that are currently enabled in the Enterprise Security (ES) module.
Correlation Searches and Notable Events
Question
How is it possible to navigate to the list of currently-enabled ES correlation searches?
Options
- AConfigure -> Correlation Searches -> Select Status "Enabled"
- BSettings -> Searches, Reports, and Alerts -> Filter by Name of "Correlation"
- CConfigure -> Content Management -> Select Type "Correlation" and Status "Enabled"
- DSettings -> Searches, Reports, and Alerts -> Select App of "SplunkEnterpriseSecuritySuite" and
How the community answered
(26 responses)- A4% (1)
- B8% (2)
- C85% (22)
- D4% (1)
Explanation
This path allows you to filter and view only the correlation searches that are currently enabled in the Enterprise Security (ES) module.
Topics
#correlation searches#Content Management#enabled searches#ES navigation
Community Discussion
No community discussion yet for this question.