Question 26

Which of the following is part of tuning correlation searches for a new ES installation?
  • Question 27

    Which columns in the Assets lookup are used to identify an asset in an event?
  • Question 28

    Following the installation of ES, an admin configured users with the ess_user role the ability to close notable events.
    How would the admin restrict these users from being able to change the status of Resolved notable events to Closed?
  • Question 29

    How should an administrator add a new lookup through the ES app?
  • Question 30

    What is the maximum recommended volume of indexing per day, per indexer, for a non-cloud (on-prem) ES deployment?