SPLK-5001 · Question #22
How are Notable Events configured in Splunk Enterprise Security?
The correct answer is D. Via an Adaptive Response Action in a correlation search. Notable Events in Splunk Enterprise Security are configured via an Adaptive Response Action attached to a correlation search (D). Correlation searches continuously monitor data for patterns matching threat conditions, and when triggered, their associated Adaptive Response…
Question
How are Notable Events configured in Splunk Enterprise Security?
Options
- ADuring an investigation.
- BAs part of an audit.
- CVia an Adaptive Response Action in a regular search.
- DVia an Adaptive Response Action in a correlation search.
How the community answered
(42 responses)- B2% (1)
- C5% (2)
- D93% (39)
Explanation
Notable Events in Splunk Enterprise Security are configured via an Adaptive Response Action attached to a correlation search (D). Correlation searches continuously monitor data for patterns matching threat conditions, and when triggered, their associated Adaptive Response Actions create Notable Events in the Incident Review dashboard - this is the designed workflow for alert-driven investigations.
Why the distractors are wrong:
- A (During an investigation): Investigations are a downstream activity that consume Notable Events; they don't create the configuration for them.
- B (As part of an audit): Audits are a reporting/compliance activity, not a mechanism for configuring event generation.
- C (Via a regular search): Regular (ad-hoc) searches are not scheduled or automated and cannot attach Adaptive Response Actions that feed the Notable Events framework - only correlation searches have this capability.
Memory tip: Think "Correlation searches Create Cases" - the three C's. Correlation searches are the security-specific search type in ES, and Notable Events are ES's version of cases/alerts, so they naturally pair together via Adaptive Response Actions.
Topics
Community Discussion
No community discussion yet for this question.