Question 26
Which of the following is part of tuning correlation searches for a new ES installation?
Question 27
Which columns in the Assets lookup are used to identify an asset in an event?
Question 28
Following the installation of ES, an admin configured users with the ess_user role the ability to close notable events.
How would the admin restrict these users from being able to change the status of Resolved notable events to Closed?
How would the admin restrict these users from being able to change the status of Resolved notable events to Closed?
Question 29
How should an administrator add a new lookup through the ES app?
Question 30
What is the maximum recommended volume of indexing per day, per indexer, for a non-cloud (on-prem) ES deployment?