Splunk doc says, Expected Views list specifies Splunk Enterprise Security views that are monitored on a regular basis. But what are these views monitored for ?
What do I need to actually use this for ? Whats the usecase behind it ?
It's for internal auditing. From the ES menu bar, if you go to Audit > View Audit... it shows the "views" (or pages in the ES app) where your admins/analysts/users are looking most often.
The Expected Views lookup is configurable, so you can add views to it if you would expect that they should be monitored daily, and then you can see if they are. You would go to Configure > Content > Content Management, then search for Expected Views, and then edit it from there.
It's for internal auditing. From the ES menu bar, if you go to Audit > View Audit... it shows the "views" (or pages in the ES app) where your admins/analysts/users are looking most often.
The Expected Views lookup is configurable, so you can add views to it if you would expect that they should be monitored daily, and then you can see if they are. You would go to Configure > Content > Content Management, then search for Expected Views, and then edit it from there.