All Apps and Add-ons

Need search query for mitre mapping of custom searches in dashboard

yashwanth_g_pra
Observer

I have search result outputs as the following,

tactictechniquesearchName
Data from Information Repositoriescollectionsearch Name A
Valid Accountspersistence
search Name B
Use Alternate Authentication Material: Pass the Ticketlateral movement
search Name C

 

and so on... I need to add a dashboard panel as shown below

 

yashwanth_g_pra_0-1700815602203.png

 

Need help in the search query for my dashboard panel where the count of the number of custom searches created is displayed for every technique.

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Index This | What’s a riddle wrapped in an enigma?

September 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

BORE at .conf25

Boss Of Regular Expression (BORE) was an interactive session run again this year at .conf25 by the brilliant ...

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...