Who can delete an investigation?
Correct Answer:
A
Reference: https://docs.splunk.com/Documentation/ES/6.1.0/Admin/Manageinvestigations
Which of the following actions can improve overall search performance?
Correct Answer:
A
How is it possible to navigate to the list of currently-enabled ES correlation searches?
Correct Answer:
A
Reference: https://docs.splunk.com/Documentation/ES/6.1.0/Admin/Listcorrelationsearches
“10.22.63.159”, “websvr4”, and “00:26:08:18: CF:1D” would be matched against what in ES?
Correct Answer:
B
How is notable event urgency calculated?
Correct Answer:
D
Reference: https://docs.splunk.com/Documentation/ES/6.1.0/User/Howurgencyisassigned