Posted by: Pdfprep
Post Date: May 19, 2021
How should an administrator add a new lookup through the ES app?
A . Upload the lookup file in Settings -> Lookups -> Lookup Definitions
B . Upload the lookup file in Settings -> Lookups -> Lookup table files
C . Add the lookup file to /etc/apps/SplunkEnterpriseSecuritySuite/lookups
D . Upload the lookup file using Configure -> Content Management -> Create New Content – > Managed Lookup
Answer: D
Explanation:
Reference: https://docs.splunk.com/Documentation/ES/6.1.0/Admin/Createlookups
Leave a Reply