SPLK-5002 · Question #107
Which action improves the effectiveness of notable events in Enterprise Security?
The correct answer is A. Applying suppression rules for false positives. Notable events in Splunk Enterprise Security (ES) are triggered by correlation searches, which generate alerts when suspicious activity is detected. However, if too many false positives occur, analysts waste time investigating non-issues, reducing SOC efficiency. How to Improve…
Question
Which action improves the effectiveness of notable events in Enterprise Security?
Options
- AApplying suppression rules for false positives
- BDisabling scheduled searches
- CUsing only raw log data in searches
- DLimiting the search scope to one index
How the community answered
(54 responses)- A81% (44)
- B4% (2)
- C9% (5)
- D6% (3)
Explanation
Notable events in Splunk Enterprise Security (ES) are triggered by correlation searches, which generate alerts when suspicious activity is detected. However, if too many false positives occur, analysts waste time investigating non-issues, reducing SOC efficiency. How to Improve Notable Events Effectiveness: Apply suppression rules to filter out known false positives and reduce alert fatigue. Refine correlation searches by adjusting thresholds and tuning event detection logic. Leverage risk-based alerting (RBA) to prioritize high-risk events. Use adaptive response actions to enrich events dynamically. By suppressing false positives, SOC analysts focus on real threats, making notable events more actionable. Thus, the correct answer is A. Applying suppression rules for false positives.
Topics
Community Discussion
No community discussion yet for this question.