What is the default schedule for accelerating ES Datamodels?
Correct Answer:B
Reference: https://docs.splunk.com/Documentation/Splunk/8.0.2/Knowledge/Acceleratedatamodels
Which component normalizes events?
Correct Answer:A
Reference: https://docs.splunk.com/Documentation/CIM/4.15.0/User/UsetheCIMtonormalizedataatsearchtime
When creating custom correlation searches, what format is used to embed field values in the title, description, and drill-down fields of a notable event?
Correct Answer:C
Reference: https://docs.splunk.com/Documentation/ITSI/4.4.2/Configure/Createcorrelationsearch
What does the risk framework add to an object (user, server or other type) to indicate increased risk?
Correct Answer:C
Reference: https://docs.splunk.com/Documentation/ES/6.1.0/User/RiskScoring
Which of the following actions can improve overall search performance?
Correct Answer:A