While looking for content tied to a new court-camera NVR sourcetype, a junior analyst only searches for a saved search whose name matches the sourcetype. What else should they include?
Select an answer to reveal the explanation.
Short Explanation
Content in ES is a whole toolkit: detections, lookups, and dashboards, not just a saved search that happens to share the NVR's name. Grep only for the sourcetype string and half the kit gets walked past. Open the whole drawer.
Full Explanation
Enterprise Security and Security Essentials content for a source includes correlation searches, supporting lookups, and Security Domain or use-case dashboards. Name-matching a single saved search under-counts what the city already has. License logs, peer lists, and dispositions are operational or workflow objects, not the content catalog. Inventory all three content types when a new sourcetype arrives.