A clerk-login failure on the treasurer workstation needs a CIM data-model search. Which data model should the analyst use?
Select an answer to reveal the explanation.
Short Explanation
A failed clerk login is a badge-reader event, not a virus event. Put it in the Authentication data model. Having a browser or a firewall nearby does not move the event into Web or Malware.
Full Explanation
CIM data models are chosen by event type. Logon success and failure belong in Authentication, not Malware, Web, or Network_Traffic. Malware is for endpoint detection of malicious files and signatures; Web is for proxy and HTTP metadata; Network_Traffic is for session flows. Using the wrong model returns empty or misleading tstats results even when the raw logon events exist.