There's a walkthrough here for how you can track content and data in your Splunk environment and how to operationalize it using different features in the Analytics Advisor section: https://docs.splunksecurityessentials.com/user/productionalize/operationalize_mitre_attack/
... View more