What does the summariesonly=true option do for a correlation search?
Answer : A
Which lookup table does the Default Account Activity Detected correlation search use to flag known default accounts?
Answer : C
What is the bar across the bottom of any ES window?
Answer : B
Following the Installation of ES, an admin configured Leers with the ss_uso r role the ability to close notable events. How would the admin restrict these users from being able to change the status of Resolved notable events to closed?
Answer : B
Which of these Is a benefit of data normalization?
Answer : A
Which of the following actions can improve overall search performance?
Answer : A
The Brute Force Access Behavior Detected correlation search is enabled, and is generating many false positives. Assuming the input data has already been validated. How can the correlation search be made less sensitive?
Answer : B