You are hunting for data exfiltration and want to identify large outbound file transfers. Which tool in Splunk is best suited to baseline 'normal' transfer volume per user?
Trap 1: Splunk DB Connect
Used for connecting to external databases.
Trap 2: Splunk Dashboard Studio
Used for visualization, not statistical baselining.
Trap 3: Splunk Add-on Builder
Used for developing add-ons, not data analysis.
- A
Splunk Machine Learning Toolkit (MLTK)
MLTK is specifically designed for baseline creation and anomaly detection.
- B
Splunk DB Connect
Why wrong: Used for connecting to external databases.
- C
Splunk Dashboard Studio
Why wrong: Used for visualization, not statistical baselining.
- D
Splunk Add-on Builder
Why wrong: Used for developing add-ons, not data analysis.