Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

CrowdStrike Certified SIEM Engineer CCSE-204 Question # 7 Topic 1 Discussion

CrowdStrike Certified SIEM Engineer CCSE-204 Question # 7 Topic 1 Discussion

CCSE-204 Exam Topic 1 Question 7 Discussion:
Question #: 7
Topic #: 1

Which field should be used in a correlation rule when detections must be based on the original event occurrence time?


A.

@ingesttimestamp


B.

@timestamp


C.

@rawstring


D.

@id


Get Premium CCSE-204 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.