Courseiva

312-39

Study mode — explanations shown

1

Incident Detection And Triage

medium

You are configuring a correlation rule in Splunk Enterprise Security. An analyst reports that too many false positives are triggered for 'Multiple Failed Login Attempts'. What is the most effective way to tune this rule?

0 of 90 answered