nerdexam
Splunk

SPLK-5001 · Question #77

A user wants to view only the use cases for which the Splunk instance has all of the supporting source types to implement. In Splunk Security Essentials, what operation needs to happen first?

The correct answer is A. Data Inventory. Before you can filter use cases by which source types you actually have, Splunk Security Essentials must first inventory your data. The Data Inventory operation scans and catalogs all source types present in your environment; only once that inventory exists can SSE determine…

Security Data Onboarding and Normalization

Question

A user wants to view only the use cases for which the Splunk instance has all of the supporting source types to implement. In Splunk Security Essentials, what operation needs to happen first?

Options

  • AData Inventory
  • BAnalytic Advisor
  • CData Availability
  • DContent Mapping

How the community answered

(54 responses)
  • A
    93% (50)
  • B
    4% (2)
  • C
    2% (1)
  • D
    2% (1)

Explanation

Before you can filter use cases by which source types you actually have, Splunk Security Essentials must first inventory your data. The Data Inventory operation scans and catalogs all source types present in your environment; only once that inventory exists can SSE determine which use cases have full support and let you view only those.

Topics

#Security Essentials#Data Inventory#source types#use case filtering

Community Discussion

No community discussion yet for this question.

Full SPLK-5001 Practice