All Apps and Add-ons

Linking a search to a use case

rafael_szt
Explorer

Hello,

First of all, I'm currently loving the Splunk Security Essentials, so many things to do with it.

One think I would like to do would be after implementing a use case, let's say Basic Scanning, somewhere that could I link the search that was implemented. Maybe on the Manage Bookmarks page?

Or maybe someone has a better approach to doing this inside Splunk?

Thank you

0 Karma

ololdach
Builder

Hi rafael_szt, there are many solutions, it really depends on what you'd like to achieve. Most likely you would probably just create a new app with a dashboard that features some graphic or report based on the search that you implemented. Oliver

0 Karma

rafael_szt
Explorer

Hello ololdach, thank you for the suggestion.

What I was thing of was mostly to have centralized the use cases that were already implemented in the Splunk Security Essentials (like the Bookmarks dashboard), and the searches that implement them.

0 Karma
Get Updates on the Splunk Community!

Fall Into Learning with New Splunk Education Courses

Every month, Splunk Education releases new courses to help you branch out, strengthen your data science roots, ...

Super Optimize your Splunk Stats Searches: Unlocking the Power of tstats, TERM, and ...

By Martin Hettervik, Senior Consultant and Team Leader at Accelerate at Iver, Splunk MVPThe stats command is ...

How Splunk Observability Cloud Prevented a Major Payment Crisis in Minutes

Your bank's payment processing system is humming along during a busy afternoon, handling millions in hourly ...