How should an administrator add a new lookup through the ES app?

Posted by: Pdfprep Category: SPLK-3001 Tags: , ,

How should an administrator add a new lookup through the ES app?
A . Upload the lookup file in Settings -> Lookups -> Lookup Definitions
B . Upload the lookup file in Settings -> Lookups -> Lookup table files
C . Add the lookup file to /etc/apps/SplunkEnterpriseSecuritySuite/lookups
D . Upload the lookup file using Configure -> Content Management -> Create New Content – > Managed Lookup

Answer: D

Explanation:

Reference: https://docs.splunk.com/Documentation/ES/6.1.0/Admin/Createlookups

Leave a Reply

Your email address will not be published.