Dashboards & Visualizations

How to create a dashboard to show the use activity

Mfmahdi
Path Finder

How to create a dashboard to show the activities of the users specially uploading files. Kindly

 

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Can you find by looking through your logs any data which indicates the behaviour you are looking for?

View solution in original post

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@Mfmahdi - You can start by searching below into your internal logs, which has both file names that were uploaded and user names who uploaded it.

index=_internal "/services/receivers/stream"

 

From here you have to first complete the search query and click on save as dashboard from your search page.

 

I hope this helps!!!

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What events have you ingested into Splunk?

0 Karma

Mfmahdi
Path Finder

we logs from linux and windows but most of our servers they are linux @ITWhisperer 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please share some anonymised examples of the events you are interested in

0 Karma

Mfmahdi
Path Finder

I 'm not allowed to search any logs. but what we are looking for is a dashboard that show is any user is uploading files in our environment @ITWhisperer  

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

How do you propose to detect whether a file has been uploaded if you don't have access to any logs?

Please describe your environment in a bit more detail and what capabilities you do have.

0 Karma

Mfmahdi
Path Finder

we do have access to all the logs, we have PowerShell , sysmon and linux ...

we need to know is any user is uploading file through PowerShell or sysmon or any data source that usually the SOC can monitor. we need to create a dashboard that shows any files activity @ITWhisperer thank you in advance 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Can you find by looking through your logs any data which indicates the behaviour you are looking for?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...