What dashboard presents a view of third-party data ingestion over the past 30 days?
What is the purpose of labels in Fleet Management?
You need to ingest data from a custom internal application hosted on-prem. The application writes logs to a file on a syslog server.
Which data connector would you use?
You suspect that an API key you recently generated has been compromised.
What should you do?
What are the four required CPS-compliant Event parser tags?
You want a consistent view of events from various data sources.
Which ECS field type should you normalize?
Which field should be used in a correlation rule when detections must be based on the original event occurrence time?
What is the most appropriate action if a third-party connector is disconnected and no longer ingesting data?
Which are valid parse functions in CQL?
A Falcon Log Collector has been configured with 4 sinks of type memory, each having a queue size of 2GB.
What is the minimum memory requirement produced by this configuration?