Solved

A Set of Correlation Searches Are Enabled at a New

Question 69

Multiple Choice

A set of correlation searches are enabled at a new ES installation, and results are being monitored. One of the correlation searches is generating many notable events which, when evaluated, are determined to be false positives. What is a solution for this issue?


A) Suppress notable events from that correlation search.
B) Disable acceleration for the correlation search to reduce storage requirements.
C) Modify the correlation schedule and sensitivity for your site.
D) Change the correlation search's default status and severity.

Correct Answer:

verifed

Verified

Unlock this answer now
Get Access to more Verified Answers free of charge

Related Questions

Unlock this Answer For Free Now!

View this answer and more for free by performing one of the following actions

qr-code

Scan the QR code to install the App and get 2 free unlocks

upload documents

Unlock quizzes for free by uploading documents