The city wants AWS CloudTrail detections for the permitting buckets. Splunk Security Essentials and Enterprise Security content search show those detections require a CloudTrail sourcetype that is not onboarded. What should the analyst tell the team?
Select an answer to reveal the explanation.
Short Explanation
Detections are recipes that need the right ingredients. If SSE says CloudTrail is required, turning the search on without CloudTrail just gives empty plates. Onboard the source, then enable the content.
Full Explanation
SSE and ES content listings expose the sourcetype and CIM prerequisites for a use case. CloudTrail detections will not produce reliable findings until CloudTrail, or the equivalent AWS API audit sourcetype, is collected and mapped. VPC Flow Logs, unbounded index=* scans, and on-prem Sysmon do not substitute for control-plane API evidence. Surface that data-source gap before claiming the detections are live.