Splunk Related Exams
SPLK-5001 Exam
An analyst is attempting to investigate a Notable Event within Enterprise Security. Through the course of their investigation they determined that the logs and artifacts needed to investigate the alert are not available.
What event disposition should the analyst assign to the Notable Event?
Which of the following is the primary benefit of using the CIM in Splunk?
What is the term for a model of normal network activity used to detect deviations?