Splunk Enterprise Security Certified Admin — Question 38
Enterprise Security's dashboards primarily pull data from what type of knowledge object?
Answer options
- A. Tstats
- B. KV Store
- C. Data models
- D. Dynamic lookups
Correct answer: C
Explanation
The correct answer is C, Data models, as they are designed to provide a structured way to access and analyze data within Enterprise Security. The other options, such as Tstats, KV Store, and Dynamic lookups, serve different purposes and do not primarily support the dashboard data retrieval in the same manner as data models.