Splunk Certification Exam Dumps
6
When ES content is exported, an app with a .spl extension is automatically created. What is the best practice when exporting and importing update to ES content?
Either use new app names or always include both existing and new content
A.
Use new app names each time content is exported
B.
Do not use the .spl extension when naming an export
C.
Always include existing and new content for each export
D.
19
How is it possible to navigate to the ES graphical Navigation Bar editor?
Setting - > User Interface -> Navigation -> Clock on "Enterprise Security"
A.
Configure -> Navigation Menu
B.
Configure -> General -> Navigation
C.
Setting -> User interface -> Navigation Menus -> Click on De"default" next to SplunkEnterpriseSecuritysuite
D.
22
Which of the following actions can improve overall search performance?
Increase priority of all correlation searches
A.
Reduce the frequency (schedule) of lower-priority correlation searches
B.
Add notable event suppressions for correlation searches with high number of false positives
C.
Disable indexed real-time search
D.
25
A site has a single existing search head which hosts a mix of both CIM and non-CIM complaint applications. All of the applications are mission-critical.The customer wants to carefully control cost, but wants good ES performance. What is the best practice for installing ES?
ADD a new search head and install ES on it
A.
Increase the number of CPUs and amount of memory on the search head, then install ES
B.
Delete the non-CIM- Complaint apps from the search head, then install ES
C.
Install ES on the existing search Head
D.
27
An administrator is asked to configure an "Nslookup" adaptive response action, so that it appears as a selectable option in the notable event�s action menu when an analyst is working in the Incident Review dashboard. What steps would the administrator take to configure this option?
Configure -> Content Management -> Type : Correlation search -> Notable -> Next Step -> Nslookup
A.
Configure -> Type: Correlation Search -> Notable -> Recommended Action -> Nslookup
B.
Configure -> Content Management -> Type : Correlation Search -> Notable -> Nslookup
C.
Configure -> content Management -> Type: Correlation Search -> Notable -> Recommended Actions -> NsLookup