Splunk Enterprise Security

After integrating a new Key Security Indicator in an Enterprise Security dashboard, how do I get the drilldown URL to point to a dashboard in my custom app?

georget
Explorer

Hi,

I've created a new Key Security Indicator for my app and have integrated it in the Security Posture dashboard of the Splunk App for Enterprise Security. I'd like the drilldown url to point to one of the dashboards of my custom app. If I try to add a URL path with slashes in the Key Indicator Search form, it is not accepted. So is it possible to reference my dashboard from the indicator?

Thanks.

0 Karma
1 Solution

georget
Explorer

I realized that if you edit savedsearches.conf and change the value of the "action.keyindicator.drilldown_uri" property of the Key Indicator search, you can specify whatever URL you want. For some reason this does not work through the Key Indicator Form in the web UI.

View solution in original post

georget
Explorer

I realized that if you edit savedsearches.conf and change the value of the "action.keyindicator.drilldown_uri" property of the Key Indicator search, you can specify whatever URL you want. For some reason this does not work through the Key Indicator Form in the web UI.

masonmorales
Influencer

Encase your URL as character data:

<![CDATA[http://www.myurl.com]]>

If that doesn't help, please post a code sample from your dashboard.

0 Karma

georget
Explorer

Thanks, but It does not work. The Key Indicator Search complains about not using a valid path. I'd like to attach a snapshot from the form where the Key Indicator Search is defined, but I am not allowed. Once I set a CDATA value in the "Drilldown URL" fields of this custom search form, I get the message:
Defines the view to redirect users to when they click the key indicator. Must be a valid path.
The form the new Key Indicator's search is defined in, is in the Custom Searches page of the ES app. There is no custom dashboard. The new Key Indicator is attached to the top panel (with the rest of the indicators) of the Security Posture dashboard of the ES app.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...