Glass tables can display static images and text, the results of ad-hoc searches, and which of the following objects?
A set of correlation searches are enabled at a new ES installation, and results are being monitored. One of the correlation searches is generating many notable events which, when evaluated, are determined to be false positives.
What is a solution for this issue?
Which of the following ES features would a security analyst use while investigating a network anomaly notable?
Which columns in the Assets lookup are used to identify an asset in an event?
“10.22.63.159”, “websvr4”, and “00:26:08:18: CF:1D” would be matched against what in ES?
After data is ingested, which data management step is essential to ensure raw data can be accelerated by a Data Model and used by ES?
What is an example of an ES asset?
Which of the following is a Web Intelligence dashboard?
Following the Installation of ES, an admin configured Leers with the ©ss_uso r role the ability to close notable events. How would the admin restrict these users from being able to change the status of Resolved notable events to closed?
Which argument to the | tstats command restricts the search to summarized data only?