A. Service swapping.
B. Service dependencies.
C. Service templates.
D. Ad-hoc search.
A. All of the above.
B. Notable event groups are created in the itsi_tracked_alerts index.
C. Notable event groups allow users to adjust threshold settings.
D. Notable event groups combine independent notable events.
A. Service & KPI tiles in the Service Analyzer.
B. Memory KPI in a glass table.
C. Memory panel of the OS Host Details view in the Operating System module.
D. Memory swim lane in a Deep Dive.
A. Enable grouping in Notable Event Review, select "Smart Mode", select "fields", and click "Save"
B. Edit the notable event view, enable smart mode, select "fields", and click "Save"
C. Edit the aggregation policy, enable smart mode, select fields to analyze, click "Save"
D. Configure -> Policies -> Smart Mode -> Enable, select "fields", click "Save"
A. Automatically associate entities to services using multiple entity aliases.
B. Being able to split a CPU usage KPI by host name.
C. All of the entities have the same identifying field name.
D. KPI total values are aggregated from multiple different category values in the source events.
A. ITSI should not be installed on search heads that have Enterprise Security installed.
B. Install ITSI on one search head in a search head cluster and migrate the configuration bundle to other search heads.
C. Before installing ITSI, make sure the Common Information Model (CIM) is installed.
D. Install the Machine Learning Toolkit app if anomaly detection must be configured.
A. Plan and implement services first, then build detailed glass tables.
B. Design glass tables first to discover which KPIs are important.
C. Start with base searches, then services, and then glass tables.
D. Always use the standard icons for glass table widgets to improve portability.
A. KPI lane.
B. Automatic lane.
C. Metric lane.
D. Event lane.
A. If this value is set to 0, the scheduler might skip some execution periods to make sure that the scheduler is executing the searches running over the most recent time range.
B. If this value is set to 0, the scheduler bases its determination of the next scheduled search on the last search execution time.
C. If this value is set to 0, the scheduler bases its determination of the next scheduled search execution time on the current time.
D. If this value is set to 0, the scheduler may skip scheduled execution periods.