When investigating, what is the best way to store a newly-found IOC?
How is it possible to navigate to the list of currently-enabled ES correlation searches?
Which of the following is a risk of using the Auto Deployment feature of Distributed Configuration Management to distribute indexes.conf?
Which of the following are data models used by ES? (Choose all that apply.)
At what point in the ES installation process should Splunk_TA_ForIndexers.spl be deployed to the indexers?
The Add-On Builder creates Splunk Apps that start with what?