A city analyst is drafting an Enterprise Security correlation search for after-hours admin logons on court case-management servers. Which dataset should that search use?
Select an answer to reveal the explanation.
Short Explanation
Correlation searches should drink from a labeled tap—an accelerated Authentication model or a tight threat or risk index. index=* every few minutes is how a SOC melts its own search heads. Constrain first, then detect.
Full Explanation
Enterprise Security correlation searches should target CIM data models or other constrained stores such as the risk or threat indexes, not an unbounded index=* scan of the whole city. Normalized, accelerated datasets keep scheduled detections fast and consistent across vendors. _internal and randomized raw indexes do not provide the Authentication CIM fields those logon detections need. Aiming the search is a SIEM best-practice skill, not an admin sizing lab.