All Apps and Add-ons

Work Instructions in SPLUNK

willadams
Contributor

I was looking at apps such as "Splunk Security Essentials" and "ATP Threat hunting" available in SPLUNK base. The apps have a great mechanism that can be user driven by clicking on tiles to open additional information. I was wondering how these are created and whether there any apps available that allows these to be created. My thought is around having a work instruction available in SPLUNK where some one has an event that they need to investigate and instead of going elsewhere be able to reference the information through a panel such as the 2 apps do above.

Tags (1)
0 Karma

Sfry1981
Communicator

the best place to start is https://dev.splunk.com/enterprise/ this should get you started on that journey

0 Karma

iainsmart
Engager

You could create a dashboard with HTML panels for the instruction text. Then using depends/rejects in the SimpleXML for the dashboard and set/unset tokens to show/hide panels depending on what is required by the workflow.

See: https://docs.splunk.com/Documentation/Splunk/latest/Viz/ContextualDrilldown

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...