The city needs malware and process context on clerk workstations, then firewall and IDS context on the same incident. Which Security Domain dashboards match those telemetry types?
Select an answer to reveal the explanation.
Short Explanation
Process trees live on Endpoint; firewall and IDS live on Network. Swapping those dashboards is like looking for a virus on the street map. Domain dashboards follow the telemetry, not the other way around.
Full Explanation
ES Security Domain dashboards are typed: Endpoint for malware and process on endpoints, Network for firewall and IDS. Mixing them sends the analyst to the wrong summaries. Security Posture is an overview, not a process-tree tool, and Incident Review Audit tracks how analysts handled notables rather than substituting for domain dashboards.