A wastewater analyst is about to write a brand-new search for historian setpoint changes. What should they do first?
Select an answer to reveal the explanation.
Short Explanation
Do not invent a historian hunt until Lantern and SSE have been checked. Supported content beats a one-off that duplicates what Splunk already documented. Python playbooks and cluster resizing are the wrong first move.
Full Explanation
Domain 5.3 expects analysts to consult Enterprise Security, Splunk Security Essentials, and Splunk Lantern before authoring one-off SPL. A wastewater hunt for historian setpoint changes may already have a mapped use case or example search. SOAR playbook authoring and indexer sizing are sibling-exam work, not the first analyst step. BOTS challenges are official prep material, not production detections to copy.