Question 71

A set of correlation searches are enabled at a new ES installation, and results are being monitored. One of the correlation searches is generating many notable events which, when evaluated, are determined to be false positives.
What is a solution for this issue?
  • Question 72

    The option to create a Short ID for a notable event is located where?
  • Question 73

    Which argument to the | tstats command restricts the search to summarized data only?
  • Question 74

    Which of the following steps will make the Threat Activity dashboard the default landing page in ES?
  • Question 75

    An administrator is provisioning one search head prior to installing ES. What are the reference minimum requirements for OS, CPU, and RAM for that machine?