On a municipal SOC, who usually creates Enterprise Security annotations on a correlation search or risk rule, and who consumes them during triage?
Select an answer to reveal the explanation.
Short Explanation
Engineers pack the box; analysts read the label on the loading dock. Annotations are authored on the correlation search or risk rule and consumed on Incident Review—not typed in by the city attorney or stamped on syslog at ingest.
Full Explanation
Annotation purpose includes a hand-off: content owners (detection engineers) attach framework metadata when they build or tune a correlation search or risk rule. Analysts consume those labels while triaging notables on Incident Review; they do not normally author the mapping as part of ticket close-out. Asset and Identity lookups, SOAR, and indexer ingest are the wrong places to create ES annotations. Knowing who writes versus who reads keeps civic SOC roles from blurring.