Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Splunk Exam SPLK-5002 Topic 5 Question 2 Discussion

Actual exam question for Splunk's SPLK-5002 exam
Question #: 2
Topic #: 5
[All SPLK-5002 Questions]

An engineer observes a high volume of false positives generated by a correlation search.

What steps should they take to reduce noise without missing critical detections?

Show Suggested Answer Hide Answer
Suggested Answer: B

How to Reduce False Positives in Correlation Searches?

High false positives can overwhelm SOC teams, causing alert fatigue and missed real threats. The best solution is to fine-tune suppression rules and refine thresholds.

How Suppression Rules & Threshold Tuning Help: Suppression Rules: Prevent repeated false positives from low-risk recurring events (e.g., normal system scans). Threshold Refinement: Adjust sensitivity to focus on true threats (e.g., changing a login failure alert from 3 to 10 failed attempts).

Example in Splunk ES: Scenario: A correlation search generates too many alerts for failed logins. Fix: SOC analysts refine detection thresholds:

Suppress alerts if failed logins occur within a short timeframe but are followed by a successful login.

Only trigger an alert if failed logins exceed 10 attempts within 5 minutes.

Why Not the Other Options?

A. Increase the frequency of the correlation search -- Increases search load without reducing false positives. C. Disable the correlation search temporarily -- Leads to blind spots in detection. D. Limit the search to a single index -- May exclude critical security logs from detection.

Reference & Learning Resources

Splunk ES Correlation Search Optimization Guide: https://docs.splunk.com/Documentation/ES Reducing False Positives in SOC Workflows: https://splunkbase.splunk.com Fine-Tuning Security Alerts in Splunk: https://www.splunk.com/en_us/blog/security


Contribute your Thoughts:

Glendora
4 days ago
I think we should add suppression rules and refine thresholds.
upvoted 0 times
...
Elvera
7 days ago
Haha, disabling the correlation search? That's like trying to fix a broken window by boarding it up completely. Option B is the way to go.
upvoted 0 times
...
Vanda
12 days ago
Option B looks good to me. Adjusting the suppression rules and thresholds should help reduce the noise without missing important detections.
upvoted 0 times
Leonora
1 days ago
User 1: I agree, adjusting suppression rules and thresholds can definitely help with reducing false positives.
upvoted 0 times
...
...

Save Cancel