Transit edge devices now send pan:threat. How should analysts find official detections and dashboards for that sourcetype?
Select an answer to reveal the explanation.
Short Explanation
Look up the sourcetype or the CIM model—pan:threat, Intrusion Detection, Malware—not the word transit on Splunkbase. SSE and ES already index content by those keys. Guessing SPL is how the supported searches get missed.
Full Explanation
Analysts should find content for a given sourcetype using Security Essentials and Enterprise Security, keyed by sourcetype or CIM model. pan:threat typically maps toward the Intrusion Detection and Malware models, so those are the right filters. Splunkbase keyword guesses, handmade dashboard XML, and license reports are not the supported content-discovery path. Locate official content before anyone authors one-off SPL.