exam questions

Exam SPLK-3001 All Questions

View all questions & answers for the SPLK-3001 exam

Exam SPLK-3001 topic 1 question 23 discussion

Actual exam question from Splunk's SPLK-3001
Question #: 23
Topic #: 1
[All SPLK-3001 Questions]

How should an administrator add a new lookup through the ES app?

  • A. Upload the lookup file in Settings -> Lookups -> Lookup Definitions
  • B. Upload the lookup file in Settings -> Lookups -> Lookup table files
  • C. Add the lookup file to /etc/apps/SplunkEnterpriseSecuritySuite/lookups
  • D. Upload the lookup file using Configure -> Content Management -> Create New Content -> Managed Lookup
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
jaemon22
3 weeks, 6 days ago
answer should be B This allows you to upload the lookup file so it can be managed and used within Splunk Enterprise Security.
upvoted 1 times
...
qtygbapjpesdayazko
1 year, 2 months ago
Selected Answer: D
Suggested Answer: D
upvoted 2 times
...
sylax
1 year, 11 months ago
Selected Answer: D
pg 242 Administering Splunk Enterprise Security 7.0
upvoted 4 times
...
andy73
2 years, 6 months ago
D is correct
upvoted 3 times
...
mi5
2 years, 7 months ago
Selected Answer: D
D is right
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago