Splunk Enterprise Security Certified Admin — Question 38

Enterprise Security's dashboards primarily pull data from what type of knowledge object?

Answer options

Correct answer: C

Explanation

The correct answer is C, Data models, as they are designed to provide a structured way to access and analyze data within Enterprise Security. The other options, such as Tstats, KV Store, and Dynamic lookups, serve different purposes and do not primarily support the dashboard data retrieval in the same manner as data models.