<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dashboard for Enterprise Security team from Misson control in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-for-Enterprise-Security-team-from-Misson-control/m-p/675795#M55333</link>
    <description>&lt;P&gt;#mission_control, # splunk cloud&lt;BR /&gt;Hi&amp;nbsp;&lt;BR /&gt;In my org primarily Mission Control events are investigated by &lt;STRONG&gt;SOC&lt;/STRONG&gt; as soon as they pop up, if futher investigation is needed the incident is escalated to &lt;STRONG&gt;Enterprise security TEAM&amp;nbsp;&lt;/STRONG&gt;who is responsible to perform deeper/detailed investigation and update back in Mission Control.&amp;nbsp;&lt;BR /&gt;USE CASE:&amp;nbsp;&lt;BR /&gt;The enterprise security manger wants a DASHBOARD which will inform him about :&amp;nbsp;&lt;BR /&gt;if the investigation is being performed by his team (ES)&amp;gt; how much average time his team member takes to resolve an incident &amp;gt; averaged over a month. &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;For ES team I have lookup file or also I can type there name(Only 7-8 people) &amp;gt; I NEED A QUERY WHICH WILL EVALUATE WHEN assigne=(tom,tim,xyz) , difference between update_time &amp;amp; create_time , averaged out over month.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Field we have :&lt;BR /&gt;&lt;EM&gt;| mcincidents &amp;nbsp; add_response_stats=true&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;| eval create_time=strtime(create_time, "%m/%d%Y %I:%M:%S %p")&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;| eval update_time=strtime(create_time, "%m/%d%Y %I:%M:%S %p")&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;| table&lt;STRONG&gt; assigne, create_time, update_time,&lt;/STRONG&gt; description, disposition, id, incident_type, name, sensitivity, source_type, summary&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 29 Jan 2024 17:01:46 GMT</pubDate>
    <dc:creator>vishenps</dc:creator>
    <dc:date>2024-01-29T17:01:46Z</dc:date>
    <item>
      <title>Dashboard for Enterprise Security team from Misson control</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-for-Enterprise-Security-team-from-Misson-control/m-p/675795#M55333</link>
      <description>&lt;P&gt;#mission_control, # splunk cloud&lt;BR /&gt;Hi&amp;nbsp;&lt;BR /&gt;In my org primarily Mission Control events are investigated by &lt;STRONG&gt;SOC&lt;/STRONG&gt; as soon as they pop up, if futher investigation is needed the incident is escalated to &lt;STRONG&gt;Enterprise security TEAM&amp;nbsp;&lt;/STRONG&gt;who is responsible to perform deeper/detailed investigation and update back in Mission Control.&amp;nbsp;&lt;BR /&gt;USE CASE:&amp;nbsp;&lt;BR /&gt;The enterprise security manger wants a DASHBOARD which will inform him about :&amp;nbsp;&lt;BR /&gt;if the investigation is being performed by his team (ES)&amp;gt; how much average time his team member takes to resolve an incident &amp;gt; averaged over a month. &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;For ES team I have lookup file or also I can type there name(Only 7-8 people) &amp;gt; I NEED A QUERY WHICH WILL EVALUATE WHEN assigne=(tom,tim,xyz) , difference between update_time &amp;amp; create_time , averaged out over month.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Field we have :&lt;BR /&gt;&lt;EM&gt;| mcincidents &amp;nbsp; add_response_stats=true&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;| eval create_time=strtime(create_time, "%m/%d%Y %I:%M:%S %p")&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;| eval update_time=strtime(create_time, "%m/%d%Y %I:%M:%S %p")&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;| table&lt;STRONG&gt; assigne, create_time, update_time,&lt;/STRONG&gt; description, disposition, id, incident_type, name, sensitivity, source_type, summary&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 17:01:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-for-Enterprise-Security-team-from-Misson-control/m-p/675795#M55333</guid>
      <dc:creator>vishenps</dc:creator>
      <dc:date>2024-01-29T17:01:46Z</dc:date>
    </item>
  </channel>
</rss>

