Splunk Related Exams
SPLK-3002 Exam
After a notable event has been closed, how long will the meta data for that event remain in the KV Store by default?
In which index are active notable events stored?
Which of the following is an advantage of using adaptive time thresholds?