Splunk Enterprise Security Certified Admin — Question 81
What are the steps to add a new column to the Notable Event table in the Incident Review dashboard?
Answer options
- A. Configure -> Incident Management -> Notable Event Statuses
- B. Configure -> Content Management -> Type: Correlation Search
- C. Configure -> Incident Management -> Incident Review Settings -> Event Management
- D. Configure -> Incident Management -> Incident Review Settings -> Table Attributes
Correct answer: D
Explanation
The correct option, D, is accurate because it directly leads to the specific settings for modifying table attributes in the Incident Review dashboard. Options A, B, and C are incorrect as they pertain to different areas of configuration that do not involve adding a new column to the Notable Event table.