SPLK-3002 Exam QuestionsBrowse all questions from this exam

SPLK-3002 Exam - Question 38


Besides creating notable events, what are the default alert actions a correlation search can execute? (Choose all that apply.)

Show Answer
Correct Answer: BCD

The default alert actions a correlation search can execute include sending an email and running a script. Sending an email is a common alert action for notifying stakeholders or taking automated action based on the results of the correlation search. Running a script allows for executing custom operations triggered by the correlation search's results. There is no built-in option for pinging a host or including the results in an RSS feed as default alert actions in most common implementations.

Discussion

2 comments
Sign in to comment
Baba111222Options: BCD
Jan 23, 2024

Correlation Searches -> "Other standard Splunk alert actions like RSS, script and email can also be executed."

nosavotor
Oct 1, 2023

Could someone please verify the accuracy of this answer