Splunk Related Exams
SPLK-5001 Exam
While investigating findings in Enterprise Security, an analyst has identified a compromised device. Without leaving ES, what action could they take to run a sequence of containment activities on the compromised device that also updates the original finding?
The field file_acl contains access controls associated with files affected by an event. In which data model would an analyst find this field?
Which of the following is a correct Splunk search that will return results in the most performant way?