Dashboards & Visualizations

How to find out who uses my Dashbaords?

sumarri
Path Finder

So, in my organization, I have have created many dashboards, but I want to know if they actually view them and how often and which roles are using/viewing them. Is is possible to get these stats from dashboards? This will be very helpful for me and my team in the future. 

 

Thank you. 

Labels (2)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

If you have access to the _audit index, run this search

index=_audit host="*" sourcetype=audittrail action=search (info=granted OR info=completed OR info=canceled) provenance=UI:dashboard*
| rex field=provenance "UI:[Dd]ashboard:(?<dashboard>.*")
| timecart count by dashboard

Note that if the provenance has D for dashboard, it is a classic Simple XML dashboard studio dashboard whereas if it's a lower case d, it is a dashboard studio dashboard.

 

View solution in original post

bowesmana
SplunkTrust
SplunkTrust

If you have access to the _audit index, run this search

index=_audit host="*" sourcetype=audittrail action=search (info=granted OR info=completed OR info=canceled) provenance=UI:dashboard*
| rex field=provenance "UI:[Dd]ashboard:(?<dashboard>.*")
| timecart count by dashboard

Note that if the provenance has D for dashboard, it is a classic Simple XML dashboard studio dashboard whereas if it's a lower case d, it is a dashboard studio dashboard.

 

richgalloway
SplunkTrust
SplunkTrust

You should be able to search for the dashboard name(s) in the _audit index.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...