What should be considered when onboarding data into a Splunk index, assuming that ITSI will need to use this data?
Which ITSI functions generate notable events? (Choose all that apply.)
There are two departments using ITSI. Finance and Sales. Analysts in each department should not be allowed to see each other's services. What are the role configuration steps required to accomplish this?