A city endpoint team just onboarded Sysmon and asks the SOC for hunts that actually use that sourcetype. Where should the analyst look first?
Select an answer to reveal the explanation.
Short Explanation
Need Sysmon hunts, and that is exactly what Security Essentials is for. SSE maps data sources to searches and bookmarks so the city does not start from a random gist. Clustering maps and APM traces are the wrong drawers.
Full Explanation
Splunk Security Essentials is the in-product library of security searches, bookmarks, and data-source mappings. When a civic SOC onboards Sysmon, SSE is the first stop to find content that actually expects that sourcetype. Unofficial gists are not blueprint SPL resources. Indexer clustering and Observability APM are sibling-platform or admin surfaces, not the 5.3 content catalog for a sourcetype.