A user reports receiving a suspicious email containing an attachment. Which Splunk ES feature allows you to quickly search for this file hash across your environment?
Trap 1: Dashboard > File Intelligence
This is not a default ES dashboard name.
Trap 2: Incident Review > Search by Hash
This is a manual workflow, not a built-in feature path.
Trap 3: Search > File Hash Investigation
This is not a native ES menu path.
- A
Enterprise Security Search bar
The primary search bar allows for immediate global searching of hashes.
- B
Dashboard > File Intelligence
Why wrong: This is not a default ES dashboard name.
- C
Incident Review > Search by Hash
Why wrong: This is a manual workflow, not a built-in feature path.
- D
Search > File Hash Investigation
Why wrong: This is not a native ES menu path.