trying to make a dashboard for overall security in splunk.
here is a few of the searches i have:
Webattacks - index=main "../etc/passwd" OR "union select" OR "javascript:" OR "
First, you should use eventtypes for failed login (windows and Unix apps should do that for your) and try to normalize your data (see the CIM standard). This will help you to simplify your queries, make them faster using the datamodel, and when you need a more advanced security solution, will simplify your migration to Enterprise Security.
They're stored within the app configuration, just like with any other app.
do you happen to know where to find the queries its using?
You should take a look at the Enterprise Security app: http://apps.splunk.com/app/263/