Question 71

A customer site is experiencing poor performance. The UI response time is high and searches take a very long time to run. Some operations time out and there are errors in the scheduler logs, indicating too many concurrent searches are being started. 6 total correlation searches are scheduled and they have already been tuned to weed out false positives.
Which of the following options is most likely to help performance?
  • Question 72

    The Brute Force Access Behavior Detected correlation search is enabled, and is generating many false positives. Assuming the input data has already been validated. How can the correlation search be made less sensitive?
  • Question 73

    What is the maximum recommended volume of indexing per day, per indexer, for a non-cloud (on-prem) ES deployment?
  • Question 74

    Following the Installation of ES, an admin configured Leers with the ess_user role the ability to close notable events. How would the admin restrict these users from being able to change the status of Resolved notable events to closed?
  • Question 75

    At what point in the ES installation process should Splunk_TA_ForIndexes.spl be deployed to the indexers?