Hi,
I'm trying to figure out what an Analytic Story is.
Is it just a collection of correlation searches grouped under one story, or does an Analytic Story raise an alert when specific conditions are met (triggering one or more correlation searches)?
Thanks
An Analytic Story in Splunk ES is more than just a collection of correlation searches. It's a comprehensive framework designed to detect, investigate, and respond to specific security threats or use cases.
The various searches that make up part of an Analytic Story can use different datasources, techniques and scenarios to provide an organisations with security monitoring against that particular goal.