Wastewater historians send a custom OT sourcetype. Splunk Security Essentials shows no matching content. What is the right next step?
Select an answer to reveal the explanation.
Short Explanation
Empty SSE is an honest answer: there is no canned OT historian pack. That is when engineering gets a build request, not when someone invents a fake OT CIM on the fly. Missing content is a signal, not a cover-up.
Full Explanation
Security Essentials is useful even when it returns no rows: it tells the analyst that default ES or SSE content does not cover that sourcetype. OT historian telemetry is commonly in that gap. Escalate to detection engineering rather than fabricating a CIM model, misapplying Windows ransomware searches, or dropping the source to hide the hole. SPLK-5001 tests recognizing the gap, not authoring the new content.