Monitoring Splunk

Splunk SOAR dashboard for monitoring

spluser1
Loves-to-Learn

Hey Everyone,

I would like to build a dashboard or use any pre-defined one in order to collect all the details of the SOAR platform and to present them in a summary report of how many active playbooks have been run and further information about successful actions and failed activities. Are there any apps that can assist with the creation of such a dashboard or any suggestions on how to do it?

i know there is one on SOAR to use, but need to build this on splunk dashboard and not using SOAR itself

 

thanks,

Efi.

Labels (1)
0 Karma

zoghiboy
Engager

you can use the "Splunk App for SOAR"

https://splunkbase.splunk.com/app/6361

 

0 Karma

marnall
Motivator

It sounds like the Splunk App for SOAR would be in the right direction: https://splunkbase.splunk.com/app/6361

 

If it does not provide the direct dashboard you want, it does provide the data with which you can build dashboards showing e.g. most active or most successful or failed playbooks in SOAR

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...