Splunk Related Exams
SPLK-5001 Exam

When threat hunting for outliers in Splunk, which of the following SPL pipelines would filter for users with over a thousand occurrences?
The field file_acl contains access controls associated with files affected by an event. In which data model would an analyst find this field?
The United States Department of Defense (DoD) requires all government contractors to provide adequate security safeguards referenced in National Institute of Standards and Technology (NIST) 800-171. All DoD contractors must continually reassess, monitor, and track compliance to be able to do business with the US government.
Which feature of Splunk Enterprise Security provides an analyst context for the correlation search mapping to the specific NIST guidelines?