Which cytool command will look up the policy being applied to a Cortex XDR agent?
Which action is required to enable use of a custom script in an alert layout?
A Cortex XSIAM engineer plans to add Kafka and Syslog Collectors to a Broker VM cluster.
What are two expected behaviors of the applets when they are added to the cluster? (Choose two.)
What is the function of the "MODEL" section when creating a data model rule?
Which two alert notification options can be configured without creating a playbook? (Choose two.)
Which two alert notification options can be configured without creating a playbook? (Choose two.)
Which field is automatically mapped from the dataset to the data model when creating a data model rule?
What should be considered when creating a custom incident domain?
An application which ingests custom application logs is hosted in an on-premises virtual environment on an Ubuntu server, and it logs locally to a .csv file.
Which set of actions will allow the ingestion of the .csv logs into Cortex XSIAM directly from the server?
An application which ingests custom application logs is hosted in an on-premises virtual environment on an Ubuntu server, and it logs locally to a .csv file.
Which set of actions will allow the ingestion of the .csv logs into Cortex XSIAM directly from the server?
Which installer type should be used when upgrading a non-Linux Kubernetes cluster?
How must Cloud Identity Engine be deployed and activated on Cortex XSIAM?