What do threat gen searches produce?
What do threat gen searches produce?
Threat gen searches are designed to produce events in the threat_activity index. These searches are part of the process of identifying and logging potential security threats based on the threat intelligence framework, which tracks and stores related events for further analysis and response.
P: 278 "The Threat Intelligence Framework"
C. Events in the threat_activity index.
Splunk Enterprise Security Admin Slides 309