ES needs to be installed on a search head with which of the following options?
Which lookup table does the Default Account Activity Detected correlation search use to flag known default accounts?
When using distributed configuration management to create the Splunk_TA_ForIndexers package, which three files can be included?
How does ES know local customer domain names so it can detect internal vs. external emails?
The Brute Force Access Behavior Detected correlation search is enabled, and is generating many false positives. Assuming the input data has already been validated. How can the correlation search be made less sensitive?
A site has a single existing search head which hosts a mix of both CIM and non-CIM compliant applications. All of the applications are mission-critical. The customer wants to carefully control cost, but wants good ES performance. What is the best practice for installing ES?
If a username does not match the ‘identity’ column in the identities list, which column is checked next?
Which of the following are examples of sources for events in the endpoint security domain dashboards?