Hi,
I am trying to create a daily alert to email the contents of the Security Posture dashboard to a recipient.
Can someone please share how I can turn the content of this Dashboard from Splunk ES into a search within an ALert so it can be added to an email and be sent out daily?
Thanks
Hi @slider8p2023,
you could try to clone it going in https://<your_host>/en-US/app/SplunkEnterpriseSecuritySuite/dashboards and cloning the dashboard, but I'm not sure that it's possible to schedule it.
Otherwise, you should create a custom clone of the Security Posture dashboard using the searches that you can extract from the original dashboard and then schedule it to send by eMail as a pdf.
Ciao.
Giuseppe
Hi @slider8p2023,
you could try to clone it going in https://<your_host>/en-US/app/SplunkEnterpriseSecuritySuite/dashboards and cloning the dashboard, but I'm not sure that it's possible to schedule it.
Otherwise, you should create a custom clone of the Security Posture dashboard using the searches that you can extract from the original dashboard and then schedule it to send by eMail as a pdf.
Ciao.
Giuseppe
Thanks @gcusello that seemed to work. I cloned the original dashboard panel by panel and saved it as a NON Dashboard studio dashboard. The schedule to export as PDF.
I was un-aware the scheduling of PDF exporting is not available in using Dashboard Studio.
Hi @slider8p2023 ,
good for you, see next time!
I still don't use Dashboard Studio because it doesn't still have all the features I use of the Classical Dashboard!
Ciao and happy splunking
Giuseppe
P.S.: Karma Points are appreciated 😉