Knowledge Management

Splunk Customized dashboard creation

sankardevarajan
Path Finder

Need a report based on previous day 
I have source ip segment xx.xx.xx.xx/28, & destination ip segment xx.xx.xx/24 

outcome of query should provide below

  • Date and start + end time of the connection
  • USERNAME
  • APPLICATION:PORT & PROTOCOL
  • APPLICATION SEGMENTS
  • ACCESS POLICY NAME
  • ACTION
    how can i create customized dashboard, please suggest.
Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Start with a search that returns the data you are interested in visualising. Do you have this already?

0 Karma

sankardevarajan
Path Finder

No. i dont have customized dasboard, can you please share some reference query?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You don't need a dashboard to create a search - just use the search and reporting interface to find the events you are interested in. Do you know what these events are?

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...