Join the discussion
Question 12/109
A newly built custom dashboard needs to be available to a team of security analysts In ES. How is It possible to Integrate the new dashboard?
Correct Answer: C
Explanation
According to the Splunk Enterprise Security documentation, the best way to integrate a newly built custom dashboard to a team of security analysts in ES is to set the dashboard permissions to allow access by es_analysts and use the navigation editor to add it to the menu. This will ensure that the dashboard is visible and accessible to the users with the es_analyst role, which is the default role for security analysts in ES. The navigation editor allows you to customize the menu bar of ES and add links to custom dashboards, reports, or other views. See Customize Splunk Enterprise Security dashboards to fit your use case and Customize the navigation bar for more details.
The other options are not recommended, because they either do not integrate the dashboard properly or they create unnecessary complexity. Adding links on the ES home page to the new dashboard is not a good option, because it does not integrate the dashboard into the menu bar and it may clutter the home page. Creating a new role inherited from es_analyst, making the dashboard permissions read-only, and making this dashboard the default view for the new role is not a good option, because it creates a redundant role and it may confuse the users who expect to see the Security Posture dashboard as the default view. Adding the dashboard to a custom add-in app and installing it to ES using the Content Manager is not a good option, because it requires creating and maintaining a separate app and it may cause conflicts or performance issues with ES. Therefore, the correct answer is C. Set the dashboard permissions to allow access by es_analysts and use the navigation editor to add it to the menu. References = Customize the navigation bar Roles and capabilities in Splunk Enterprise Security Content Management Customize Splunk Enterprise Security dashboards to fit your use case How to Create Custom Dashboards and Alerts to Achi ... - Splunk Community

According to the Splunk Enterprise Security documentation, the best way to integrate a newly built custom dashboard to a team of security analysts in ES is to set the dashboard permissions to allow access by es_analysts and use the navigation editor to add it to the menu. This will ensure that the dashboard is visible and accessible to the users with the es_analyst role, which is the default role for security analysts in ES. The navigation editor allows you to customize the menu bar of ES and add links to custom dashboards, reports, or other views. See Customize Splunk Enterprise Security dashboards to fit your use case and Customize the navigation bar for more details.
The other options are not recommended, because they either do not integrate the dashboard properly or they create unnecessary complexity. Adding links on the ES home page to the new dashboard is not a good option, because it does not integrate the dashboard into the menu bar and it may clutter the home page. Creating a new role inherited from es_analyst, making the dashboard permissions read-only, and making this dashboard the default view for the new role is not a good option, because it creates a redundant role and it may confuse the users who expect to see the Security Posture dashboard as the default view. Adding the dashboard to a custom add-in app and installing it to ES using the Content Manager is not a good option, because it requires creating and maintaining a separate app and it may cause conflicts or performance issues with ES. Therefore, the correct answer is C. Set the dashboard permissions to allow access by es_analysts and use the navigation editor to add it to the menu. References = Customize the navigation bar Roles and capabilities in Splunk Enterprise Security Content Management Customize Splunk Enterprise Security dashboards to fit your use case How to Create Custom Dashboards and Alerts to Achi ... - Splunk Community

Add Comments
- Other Question (109q)
- Q1. When investigating, what is the best way to store a newly-found IOC?...
- Q2. In order to include an eventtype in a data model node, what is the next step after extract...
- Q3. ES needs to be installed on a search head with which of the following options?...
- Q4. Which of the following threat intelligence types can ES download? (Choose all that apply)...
- Q5. Which of the following is a way to test for a property normalized data model?...
- Q6. What role should be assigned to a security team member who will be taking ownership of not...
- Q7. Where should an ES search head be installed?
- Q8. When creating custom correlation searches, what format is used to embed field values in th...
- Q9. A site has a single existing search head which hosts a mix of both CIM and non-CIM complia...
- Q10. What is the bar across the bottom of any ES window?...
- Q11. Which of the following is an adaptive action that is configured by default for ES?...
- Q12. A newly built custom dashboard needs to be available to a team of security analysts In ES....
- Q13. Accelerated data requires approximately how many times the daily data volume of additional...
- Q14. Which of the following are examples of sources for events in the endpoint security domain ...
- Q15. What feature of Enterprise Security downloads threat intelligence data from a web server?...
- Q16. Which of the following actions may be necessary before installing ES?...
- Q17. What is an example of an ES asset?
- Q18. Which data model is commonly used for authentication monitoring in Splunk Enterprise Secur...
- Q19. What can be exported from ES using the Content Management page?...
- Q20. An administrator is provisioning one search head prior to installing ES. What are the refe...
- Q21. Which tool is used to update indexers in ES?
- Q22. What feature of Enterprise Security downloads threat intelligence data from a web server?...
- Q23. Which of the following features can the Add-on Builder configure in a new add-on?...
- Q24. Which two fields combine to create the Urgency of a notable event?...
- Q25. Glass tables can display static images and text, the results of ad-hoc searches, and which...
- Q26. Where is it possible to export content, such as correlation searches, from ES?...
- Q27. What tools does the Risk Analysis dashboard provide?...
- Q28. What can be exported from ES using the Content Management page?...
- Q29. What feature of Enterprise Security downloads threat intelligence data from a web server?...
- Q30. What role should be assigned to a security team member who will be taking ownership of not...
- Q31. When ES content is exported, an app with a .splextension is automatically created. What is...
- Q32. Which column in the Asset or Identity list is combined with event security to make a notab...
- Q33. The Remote Access panel within the User Activity dashboard is not populating with the most...
- Q34. What kind of value is in the red box in this picture? (Exhibit)...
- Q35. After installing Enterprise Security, the distributed configuration management tool can be...
- Q36. ES needs to be installed on a search head with which of the following options?...
- Q37. Which lookup table does the Default Account Activity Detected correlation search use to fl...
- Q38. Where is it possible to export content, such as correlation searches, from ES?...
- Q39. What is the first step when preparing to install ES?...
- Q40. What is the main purpose of the Threat Intelligence Framework in Splunk ES?...
- Q41. Which of the following are the default ports that must be configured for Splunk Enterprise...
- Q42. Which of the following actions may be necessary before installing ES?...
- Q43. A site has a single existing search head which hosts a mix of both CIM and non-CIM complia...
- Q44. The option to create a Short ID for a notable event is located where?...
- Q45. Where are attachments to investigations stored?...
- Q46. A set of correlation searches are enabled at a new ES installation, and results are being ...
- Q47. What role should be assigned to a security team member who will be taking ownership of not...
- Q48. Which of the following lookup types in Enterprise Security contains information about know...
- Q49. The Brute Force Access Behavior Detected correlation search is enabled, and is generating ...
- Q50. Which of the following threat intelligence types can ES download? (Choose all that apply.)...
- Q51. Which two fields combine to create the Urgency of a notable event?...
- Q52. The Remote Access panel within the User Activity dashboard is not populating with the most...
- Q53. What are adaptive responses triggered by?
- Q54. What tools does the Risk Analysis dashboard provide?...
- Q55. When using distributed configLradon management to create the spiunk_TA_Forindexers package...
- Q56. Who can delete an investigation?
- Q57. Which settings indicates that the correlation search will be executed as new events are in...
- Q58. Which Splunk ES feature helps analysts investigate relationships between users, systems, a...
- Q59. Which correlation search feature is used to throttle the creation of notable events?...
- Q60. What feature of Enterprise Security downloads threat intelligence data from a web server?...
- Q61. A security manager has been working with the executive team on long-range security goals. ...
- Q62. A site has a single existing search head which hosts a mix of both CIM and non-CIM complia...
- Q63. Which columns in the Assets lookup are used to identify an asset in an event?...
- Q64. What can be exported from ES using the Content Management page?...
- Q65. To observe what network services are in use in a network's activity overall, which of the ...
- Q66. Adaptive response action history is stored in which index?...
- Q67. When installing Enterprise Security, what should be done after installing the add-ons nece...
- Q68. ES needs to be installed on a search head with which of the following options?...
- Q69. How is it possible to navigate to the list of currently-enabled ES correlation searches?...
- Q70. A security manager has been working with the executive team en long-range security goals. ...
- Q71. What does the Security Posture dashboard display?...
- Q72. What should be used to map a non-standard field name to a CIM field name?...
- Q73. Which column in the Asset or Identity list is combined with event security to make a notab...
- Q74. If a username does not match the 'identity' column in the identities list, which column is...
- Q75. Glass tables can display static images and text, the results of ad-hoc searches, and which...
- Q76. Which of the following are examples of sources for events in the endpoint security domain ...
- Q77. Which of the following are examples of sources for events in the endpoint security domain ...
- Q78. Which settings indicated that the correlation search will be executed as new events are in...
- Q79. Glass tables can display static images and text, the results of ad-hoc searches, and which...
- Q80. Which component normalizes events?
- Q81. When using distributed configuration management to create the Splunk_TA_ForIndexerspackage...
- Q82. An administrator is asked to configure an "Nslookup" adaptive response action, so that it ...
- Q83. Which of the following is an adaptive action that is configured by default for ES?...
- Q84. Which two fields combine to create the Urgency of a notable event?...
- Q85. Which component normalizes events?
- Q86. Both "Recommended Actions" and "Adaptive Response Actions" use adaptive response. How do t...
- Q87. How is it possible to navigate to the list of currently-enabled ES correlation searches?...
- Q88. Which of the following are the default ports that must be configured for Splunk Enterprise...
- Q89. What does the Security Posture dashboard display?...
- Q90. The Brute Force Access Behavior Detected correlation search is enabled, and is generating ...
- Q91. An administrator wants to ensure that none of the ES indexed data could be compromised thr...
- Q92. Which columns in the Assets lookup are used to identify an asset in an event?...
- Q93. Which data model populated the panels on the Risk Analysis dashboard?...
- Q94. Which of the following are examples of sources for events in the endpoint security domain ...
- Q95. How is notable event urgency calculated?
- Q96. Enterprise Security's dashboards primarily pull data from what type of knowledge object?...
- Q97. Which data model populates the panels on the Risk Analysis dashboard?...
- Q98. Which of the following is a key feature of a glass table?...
- Q99. What is the default schedule for accelerating ES Datamodels?...
- Q100. How is it possible to navigate to the list of currently-enabled ES correlation searches?...
- Q101. The Add-On Builder creates Splunk Apps that start with what?...
- Q102. ES needs to be installed on a search head with which of the following options?...
- Q103. Which data model populates the panels on the Risk Analysis dashboard?...
- Q104. The Brute Force Access Behavior Detected correlation search is enabled, and is generating ...
- Q105. Which of the following is a Web Intelligence dashboard?...
- Q106. What do threat gen searches produce?
- Q107. What is the maximum recommended volume of indexing per day, per indexer, for a non-cloud (...
- Q108. What tools does the Risk Analysis dashboard provide?...
- Q109. How is it possible to navigate to the ES graphical Navigation Bar editor?...
