A is correct
You can improve overall performance by making less critical correlation
searches scheduled instead of real-time
Administering Splunk Enterprise Security page 228
C is correct. Page 328 of Administering Splunk Enterprise Security
"ES automatically configures Splunk to use indexed real time searching
Improves concurrent real time search performance at the cost of a small delay in delivering real time results from searches
Leave turned on in ES for best performance"
This slide invalidates A. being the answer.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
guirax
Highly Voted 3 years, 4 months agomarinatedcohort
Most Recent 3 months, 2 weeks ago8e3ad88
9 months, 1 week agormn11
1 year, 10 months agomarinatedcohort
3 months, 2 weeks agoIGoddard90
1 year, 11 months agoRedYeti
1 year, 3 months agoBMO
3 years, 11 months ago1qaz2wsx
3 years, 7 months ago