SPLK-1004 Exam QuestionsBrowse all questions from this exam

SPLK-1004 Exam - Question 3


What default Splunk role can use the Log Event alert action?

Show Answer
Correct Answer: A

The default Splunk role 'Power' is capable of using the Log Event alert action. The Power role has the necessary permissions to utilize this feature, allowing for effective logging and alerting within the platform.

Discussion

4 comments
Sign in to comment
DeragOption: A
Apr 15, 2024

A power user with edit_tcp capability can use the log event. The Admin role is required to edit/modify it.

Eddie_examOption: D
Apr 21, 2024

Correct answer is the Admin user. Power user needs the edit_tcp capability. See Fundamentals 3 slide 108.

jaemon22Option: C
May 31, 2024

It's C

jaemon22Option: A
May 31, 2024

Correction answer is A, the answer C i provided earlier was for anoher question.