A new courts-SOC analyst thinks reusable security SPL exists only in the Search app. Where else in Enterprise Security should they look?
Select an answer to reveal the explanation.
Short Explanation
The Search app is not the only drawer of working security SPL. ES itself ships correlation-search definitions, investigation workbench searches, and Security Domain drilldowns. Clustering, license, and KV Store screens are admin furniture, not the analyst's SPL library.
Full Explanation
Blueprint 5.3 treats Enterprise Security as an SPL resource: analysts reuse searches from correlation-search definitions, the investigation workbench, and Security Domain dashboard drilldowns, not only ad-hoc Search-app queries. Indexer clustering, license-master usage, and KV Store administration are ES Admin / platform work and are not where civic analysts copy investigation SPL. Opening those ES objects gives tested, CIM-aware starting points for a courts case.