You find a Falcon Log Collector instance on a Linux system that is not connected to Fleet Management.
What command would you use to enroll the Falcon Log Collector?
Review the log sample below:

What type of parser should be used to extract fields and values from this log?
Which combination of scope and permissions must be configured to create an API token that allows you to create and get the results of a query job in Next-Gen SIEM?
You are reviewing a lookup file to determine whether an event was successfully parsed during ingestion.
Which metadata field indicates the event’s parsing status?
You notice a larger than expected ingest delay from one of your high-volume streaming log collectors.
Which setting should you increase on the log collector to improve performance?
Which role is most appropriate when a user only needs to view SIEM investigations and dashboards but must not modify content?
Which function is most appropriate for extracting fields from logs formatted as key=value pairs?
Which field should be used in a correlation rule when detections must be based on the original event occurrence time?
You need to import a pre-built workflow into Fusion SOAR to automate a part of your incident response process.
Which file format would you use?
Which CQL statement below includes correct placement of the AND statements and the pipe symbol?
Review the log event below:
{"ts": "2018/11/01 14:31:10", "server": "web01", "message": "Out of memory"}
Which parsing function is correct to add a missing timezone field?