Splunk
SPLK-5002 · Question #5
Which tool can help provide a baseline of the data sources in a given Splunk environment?
The correct answer is B. Enterprise Security Data Library. The Enterprise Security Data Library (ESDL) provides a baseline of the data sources available in a Splunk environment. It helps identify which data sources are present, how they map to security use cases, and whether they align with Enterprise Security requirements.
Splunk Basics
Question
Which tool can help provide a baseline of the data sources in a given Splunk environment?
Options
- AEnterprise Security Content Update
- BEnterprise Security Data Library
- CSplunk Security Essentials Analytic Stories
- DSplunk Security Essentials Data Inventory
How the community answered
(34 responses)- A6% (2)
- B74% (25)
- C3% (1)
- D18% (6)
Explanation
The Enterprise Security Data Library (ESDL) provides a baseline of the data sources available in a Splunk environment. It helps identify which data sources are present, how they map to security use cases, and whether they align with Enterprise Security requirements.
Topics
#Security Essentials#data inventory#data sources#baseline
Community Discussion
No community discussion yet for this question.