Dashboards & Visualizations

How to create a dashboard that shows the total number of emails stopped by reputation filter Ironport?

Ghanayem1974
Path Finder

I want to create a dashboard that shows the total number of emails stopped by IronPort, along with Invalid recipients, spam but I am not sure what search I should start with.

0 Karma
1 Solution

adonio
Ultra Champion

hello there
onboard the ironport logs
leverage pre-built splunk apps for cisco: (i think this is the proper one)
https://splunkbase.splunk.com/app/1761/#/overview
read about the app here:
http://docs.splunk.com/Documentation/AddOns/latest/CiscoESA/About
search the data and the interesting fields and build your queries for panels in dashboard
or download the cisco security suite https://splunkbase.splunk.com/app/525/
which has some pre-built dashboards around your use case

example:

alt text

hope it helps

View solution in original post

0 Karma

adonio
Ultra Champion

hello there
onboard the ironport logs
leverage pre-built splunk apps for cisco: (i think this is the proper one)
https://splunkbase.splunk.com/app/1761/#/overview
read about the app here:
http://docs.splunk.com/Documentation/AddOns/latest/CiscoESA/About
search the data and the interesting fields and build your queries for panels in dashboard
or download the cisco security suite https://splunkbase.splunk.com/app/525/
which has some pre-built dashboards around your use case

example:

alt text

hope it helps

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...