Getting Data In

Splunk Assistance: How to create dashboards in Splunk?

SplunkDummy33
New Member

I am a student at Embry-Riddle Aeronautical University and i am attending MISA 532 Intgd Threat Warning Attk EIS. Our semester project is to create a dashboard using Splunk and adding panels each week. I am requesting assistance because i have been able to download Splunk successfully but have not been able to use Splunk to create dashboards. I am asking if someone can assist me in dashboard creations to be able to fulfill my class requirements. 

I am tasked to create three panels;

  • Access Denied/Privilege Escalation. how many failed attempts or PE were recorded.
  • Failed Log in. How many failed login attempts were detected by company users.
  • Social Media (OSINT). A dashboard showing OSINT information for employees. 
Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @SplunkDummy33,

your question is just a little vague, because, before arriving to create a dashboard, you should have ingested the data in your Splunk and have the knowledge to create the search that's the base for each dashboard, then you should know the matter of your dashboard (in your case MISA 532 Intgd Threat Warning Attk EIS) that means to know the fields and values that you can find in your data.

In other words: dashboards is the last step in your activity!

About data ingestion, see some video about getting data in: https://www.google.com/search?q=splunk+getting+data+in&rlz=1C1VDKB_itIT1048IT1048&oq=splunk+getting+...

About search creation, see the Splunk Search Tutotial: https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchTutorial/WelcometotheSearchTutorial

At least, about  dashboard (using Dashboard Studio), you can see at: https://www.google.com/search?q=splunk+dashboard+studio&sca_esv=559635945&rlz=1C1VDKB_itIT1048IT1048...

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2024 Splunk Career Impact Report

We’ve been buzzing with excitement about the recent validation of Splunk Education! The 2024 Splunk Career ...

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...