Status of detection analytics
The following table displays the various statuses of detection analytics:
Status | Explanation |
---|---|
Production | Fully tested detections in the Splunk Enterprise Security environment with the latest Splunk TAs installed against the associated attack data. |
Experimental | No associated attack data available because it was not possible to simulate the attack, or the attack data contains sensitive information that could not be published to our attack data repository. |
Deprecated | Deprecated detections that Splunk no longer supports or maintains. Usually, the description of a deprecated detection has a note explaining the reason for the deprecation of the detection and information on a replacement detection, if available. |