Splunk Related Exams
SPLK-5001 Exam
Which of the following is a correct Splunk search that will return results in the most performant way?
Which dashboard in Enterprise Security would an analyst use to generate a report on users who are currently on a watchlist?
While investigating findings in Enterprise Security, an analyst has identified a compromised device. Without leaving ES, what action could they take to run a sequence of containment activities on the compromised device that also updates the original finding?