Splunk Enterprise Security

Adding key indicator search to custom dashboard in Splunk Enterprise Security



I'm trying to add new/existing key indicator searches to my dashboard in ES, but the edit toolbar does not have the "Add Key Indicator" button.

My custom dashboard:

My custom dashboardMy custom dashboard

Default dashboard with Key Indicators:

Default dashboard with Key IndicatorDefault dashboard with Key Indicator

I also tried to clone the default "Email Activity" dashboard (which has existing key indicators in it), but the clone dashboard cannot be loaded.


What should I do?

If this is a bug, which log files do I need to check?


Thank you. 

Labels (3)
0 Karma


Hello @ThuLe,

There should be input available in the dropdown menu - 



Can you please confirm if this is something you are looking for? Please accept the solution and hit Karma, if this helps!

0 Karma


Hello, Just checking through if the issue was resolved or you have any further questions?

0 Karma
Get Updates on the Splunk Community!

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...

The Great Resilience Quest: 10th Leaderboard Update

The tenth leaderboard update (11.23-12.05) for The Great Resilience Quest is out >> As our brave ...