A county just started sending WinEventLog:Security from the sheriff records LAN. How should the analyst find which detections that sourcetype unlocks?
Select an answer to reveal the explanation.
Short Explanation
Security Essentials is the catalog: feed it the new Windows sourcetype and it shows which detections just became possible. That is faster and safer than inventing a SOAR playbook to guess. New source in, content list out.
Full Explanation
Splunk Security Essentials is the tool for assessing a sourcetype and listing content that source can support. After WinEventLog:Security starts arriving from a civic LAN, use SSE data-source and content views rather than guessing SPL or writing a playbook. The Risk Analysis dashboard shows risk objects and scores, not a sourcetype-to-content catalog. Unfocused Splunkbase browsing is not the official content-discovery method.