All Apps and Add-ons

Work Instructions in SPLUNK

willadams
Contributor

I was looking at apps such as "Splunk Security Essentials" and "ATP Threat hunting" available in SPLUNK base. The apps have a great mechanism that can be user driven by clicking on tiles to open additional information. I was wondering how these are created and whether there any apps available that allows these to be created. My thought is around having a work instruction available in SPLUNK where some one has an event that they need to investigate and instead of going elsewhere be able to reference the information through a panel such as the 2 apps do above.

Tags (1)
0 Karma

Sfry1981
Communicator

the best place to start is https://dev.splunk.com/enterprise/ this should get you started on that journey

0 Karma

iainsmart
Engager

You could create a dashboard with HTML panels for the instruction text. Then using depends/rejects in the SimpleXML for the dashboard and set/unset tokens to show/hide panels depending on what is required by the workflow.

See: https://docs.splunk.com/Documentation/Splunk/latest/Viz/ContextualDrilldown

0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...