Exam SPLK-3001 All QuestionsBrowse all questions from this exam
Question 46

Where are attachments to investigations stored?

    Correct Answer: A

    Attachments to investigations in Splunk Enterprise Security are stored in the KV Store. The KV Store is used to manage lookups and collections, making it well-suited for storing such data. This is consistent with the general usage of the KV Store for maintaining various types of supplementary data within Splunk.

Discussion
andy73Option: A

A is correct. Some lookups are managed by the KV store Examples: incident review, threat intel collections