A is correct
You can improve overall performance by making less critical correlation
searches scheduled instead of real-time
Administering Splunk Enterprise Security page 228
C is correct. Page 328 of Administering Splunk Enterprise Security
"ES automatically configures Splunk to use indexed real time searching
Improves concurrent real time search performance at the cost of a small delay in delivering real time results from searches
Leave turned on in ES for best performance"
This slide invalidates A. being the answer.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
guirax
Highly Voted 3 years, 2 months agomarinatedcohort
Most Recent 1 month, 1 week ago8e3ad88
7 months agormn11
1 year, 8 months agomarinatedcohort
1 month, 1 week agoIGoddard90
1 year, 9 months agoRedYeti
1 year agoBMO
3 years, 9 months ago1qaz2wsx
3 years, 4 months ago