When using distributed configuration management to create the Splunk_TA_ForIndexers package, which three files can be included?
How does ES know local customer domain names so it can detect internal vs. external emails?
The Brute Force Access Behavior Detected correlation search is enabled, and is generating many false positives. Assuming the input data has already been validated. How can the correlation search be made less sensitive?
Adaptive response action history is stored in which index?