Public health's cloud EHR is SaaS and has no Splunk-supported ehr:cim sourcetype. How should the analyst assess useful data?
Select an answer to reveal the explanation.
Short Explanation
A log the SaaS vendor does not emit cannot be collected. For a cloud EHR, that usually means the identity provider and the proxy or CASB, not a made-up ehr:cim sourcetype. Assess the doors that can actually be watched.
Full Explanation
Many civic SaaS applications have no first-class Splunk CIM sourcetype. Useful evidence is whatever the environment actually produces—commonly identity-provider sign-ins and CASB, reverse-proxy, or Web-model traffic. Inventing ehr:cim, waiting indefinitely for a vendor model, or substituting DHCP does not create EHR audit quality. SSE and ES assessment should list collectable sources, not fictional ones.