Splunk
SPLK-5001 · Question #95
An analyst needs to send notification emails after investigating a particular type of finding. Which feature should they ask an engineer to enable that will allow them to do so directly from Splunk…
The correct answer is B. Adaptive Response Action. By enabling an Adaptive Response Action for email in Splunk ES, analysts can trigger and send notification emails directly from the Incident Review workflow once they’ve investigated a notable
Incident Investigation and Response
Question
An analyst needs to send notification emails after investigating a particular type of finding. Which feature should they ask an engineer to enable that will allow them to do so directly from Splunk ES?
Options
- ASplunk add-on for Email
- BAdaptive Response Action
- CEmail plug-in
- DInclude in Next Steps
How the community answered
(37 responses)- A8% (3)
- B86% (32)
- C3% (1)
- D3% (1)
Explanation
By enabling an Adaptive Response Action for email in Splunk ES, analysts can trigger and send notification emails directly from the Incident Review workflow once they’ve investigated a notable
Topics
#Adaptive Response#alert actions#Splunk ES#notification
Community Discussion
No community discussion yet for this question.