nerdexam
Splunk

SPLK-3002 · Question #12

Besides creating notable events, what are the default alert actions a correlation search can execute? (Choose all that apply.)

The correct answer is B. Send email. C. Include in RSS feed. D. Run a script. Throttling applies to any correlation search alert type, including notable events and actions (RSS feed, email, run script, and ticketing). B, C, and D are correct answers because they are the default alert actions that a correlation search can execute besides creating notable…

Anomaly Detection and Notable Events

Question

Besides creating notable events, what are the default alert actions a correlation search can execute? (Choose all that apply.)

Options

  • APing a host.
  • BSend email.
  • CInclude in RSS feed.
  • DRun a script.

How the community answered

(40 responses)
  • A
    13% (5)
  • B
    88% (35)

Explanation

Throttling applies to any correlation search alert type, including notable events and actions (RSS feed, email, run script, and ticketing). B, C, and D are correct answers because they are the default alert actions that a correlation search can execute besides creating notable events. You can configure a correlation search to send an email, include the results in an RSS feed, or run a custom script when the search matches a defined pattern. Ping a host is not a default alert action for correlation searches.

Topics

#correlation search#alert actions#email#RSS feed

Community Discussion

No community discussion yet for this question.

Full SPLK-3002 Practice