A housing-authority account shows logons at improbable hours from an unusual geography and a sudden volume spike. The lead says it might be a DDoS dashboard problem. Which ES view is actually built for that access pattern?
Select an answer to reveal the explanation.
Short Explanation
A 3 a.m. logon from another country is an access-anomaly problem, not a DDoS weather map. Access Anomalies is built for weird time, place, and volume on accounts. Don't send that to packet decode or the audit log.
Full Explanation
Access Anomalies surfaces improbable access patterns—time, geography, and volume—for identities. It is not a DDoS or packet-decode dashboard. Protocol Intelligence may show protocol floods when Stream is present, Security Posture summarizes notables, and Incident Review Audit records how analysts handled queue items. For suspicious civic access, Access Anomalies is the matching 4.5 view.