A behavioral hunt finds several odd but individually weak actions on a permitting clerk identity. How should those findings feed Enterprise Security?
Select an answer to reveal the explanation.
Short Explanation
Think of each odd click as a pebble, not a siren. Drop those pebbles onto the clerk's risk object and let Risk-Based Alerting add them up. One notable per pebble is how a permit desk becomes an alert landfill.
Full Explanation
Behavioral hunting often yields weak signals that matter in combination. Risk-Based Alerting is designed to write those behaviors as risk events on a user or system so contributing events raise a risk notable instead of flooding Incident Review. Waiting for a hash, auto-disabling the clerk, or creating a notable per action wastes the hunt-to-RBA pattern that Splunk ES provides.