A small city's Splunk Security Essentials data-source checklist shows rich firewall syslog but no DNS. Command-and-control content is marked weak. What should the analyst conclude?
Select an answer to reveal the explanation.
Short Explanation
Firewall logs see connections; DNS logs see the names those connections asked for. If SSE says DNS is missing, C2 hunts that key on resolver data are flying half-blind. Add DNS—do not unplug the firewall to silence the checklist.
Full Explanation
Splunk Security Essentials data-source views highlight which telemetry a use case needs. Many command-and-control detections depend on DNS resolver or passive-DNS fields that firewall allow/deny syslog does not reliably provide. A small city with only firewall coverage should treat the DNS gap as a collection priority rather than assuming deny logs fill it. Disabling a healthy firewall sourcetype only reduces coverage further.