A parks-department SOC lead needs analysts to keep Enterprise Security, Splunk Security Essentials, and Splunk Lantern straight. Which assignment is correct?
Select an answer to reveal the explanation.
Short Explanation
Three tools, three jobs: ES is the live SIEM where notables live, SSE is the in-product catalog of searches and data-source maps, and Lantern is the public official how-to site. Swap those labels and parks analysts look in the wrong building.
Full Explanation
Enterprise Security is the runtime SIEM: correlation searches, notables, dashboards, and investigation workbench. Splunk Security Essentials is in-product content discovery—searches, bookmarks, and sourcetype mappings—while Splunk Lantern is the public official playbook and use-case site with example searches. Confusing those roles sends a civic analyst to a blog, an install lab, or a SOAR editor when they needed a documented search. Blueprint 5.3 tests that distinction, not playbook authoring or indexer sizing.