The public-health SOC needs an official Splunk how-to for investigating ransomware, including example searches. Which resource is that library?
Select an answer to reveal the explanation.
Short Explanation
Lantern is Splunk's public how-to shelf: ransomware investigation, DNS exfil, RBA, SOAR triggers, with example searches. Marketing PDFs, the ES install guide, and CySA+ flashcards are not that library.
Full Explanation
Splunk Lantern publishes official security use-case guides—including ransomware investigation, DNS exfiltration, risk-based alerting, and SOAR trigger patterns—with example searches a civic analyst can adapt. That is the named 5.3 resource for official how-to SPL and workflows. Vendor marketing, ES Admin install labs, and vendor-neutral CompTIA items are not Splunk's security-search library. Public-health SOC should start on Lantern, then adapt searches to local indexes.