Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Splunk Exam SPLK-3001 Topic 1 Question 73 Discussion

Actual exam question for Splunk's SPLK-3001 exam
Question #: 73
Topic #: 1
[All SPLK-3001 Questions]

Following the installation of ES, an admin configured users with the ess_user role the ability to close notable events.

How would the admin restrict these users from being able to change the status of Resolved notable events to Closed?

Show Suggested Answer Hide Answer
Suggested Answer: A

Contribute your Thoughts:

Gussie
19 days ago
Option C looks promising. By removing the ess_user from the status transitions for the Closed status, they won't be able to change the status of Resolved notable events.
upvoted 0 times
...
Elizabeth
1 months ago
Haha, if the admin wants to really mess with the ess_users, they should just change the Closed status to 'Classified' and watch them scratch their heads.
upvoted 0 times
Jennie
2 days ago
C) Haha, that would definitely confuse them! But for a more practical approach, the admin should go with option B.
upvoted 0 times
...
Jolene
10 days ago
B) From the Status Configuration window select the Closed status. Remove ess_user from the status transitions for the Resolved status.
upvoted 0 times
...
Billye
17 days ago
A) In Enterprise Security, give the ess_user role the Own Notable Events permission.
upvoted 0 times
...
...
Bernadine
1 months ago
I'm not sure if Option D is the right choice. Removing the edit_notable_events capability might have unintended consequences.
upvoted 0 times
...
Gerald
2 months ago
Option B seems the way to go. Removing the ess_user role from the status transitions for the Resolved status will do the trick.
upvoted 0 times
Clement
22 days ago
User 2: Agreed, removing ess_user from the status transitions for the Resolved status will prevent them from changing the status to Closed.
upvoted 0 times
...
Miss
1 months ago
User 1: I think option B is the best choice.
upvoted 0 times
...
...
Kristal
2 months ago
But wouldn't giving the ess_user role the Own Notable Events permission also help restrict them from closing events?
upvoted 0 times
...
Erick
2 months ago
I agree with Gerald. That way, ess_user won't be able to change the status of Resolved notable events to Closed.
upvoted 0 times
...
Gerald
2 months ago
I think the admin should remove ess_user from the status transitions for the Closed status.
upvoted 0 times
...

Save Cancel