A wastewater SOC analyst is told to use SPL against civic indexes and the Authentication data model while scoping a notable. What is SPL in that workflow?
Select an answer to reveal the explanation.
Short Explanation
SPL is the language you type into Splunk, not a dashboard hanging on the wall. When the wastewater crew scopes a notable, they search indexes and data models in SPL. Dashboards and lookups are other ES objects, not the language.
Full Explanation
SPL (Search Processing Language) is how analysts and correlation searches query Splunk indexes and data models. In Enterprise Security it is the investigation and detection language, not a dashboard family, an Adaptive Response host service, or an Asset and Identity lookup. Knowing that distinction keeps Domain 4 term questions from being confused with dashboard or identity-framework work.