Splunk Enterprise Security

After integrating a new Key Security Indicator in an Enterprise Security dashboard, how do I get the drilldown URL to point to a dashboard in my custom app?

georget
Explorer

Hi,

I've created a new Key Security Indicator for my app and have integrated it in the Security Posture dashboard of the Splunk App for Enterprise Security. I'd like the drilldown url to point to one of the dashboards of my custom app. If I try to add a URL path with slashes in the Key Indicator Search form, it is not accepted. So is it possible to reference my dashboard from the indicator?

Thanks.

0 Karma
1 Solution

georget
Explorer

I realized that if you edit savedsearches.conf and change the value of the "action.keyindicator.drilldown_uri" property of the Key Indicator search, you can specify whatever URL you want. For some reason this does not work through the Key Indicator Form in the web UI.

View solution in original post

georget
Explorer

I realized that if you edit savedsearches.conf and change the value of the "action.keyindicator.drilldown_uri" property of the Key Indicator search, you can specify whatever URL you want. For some reason this does not work through the Key Indicator Form in the web UI.

masonmorales
Influencer

Encase your URL as character data:

<![CDATA[http://www.myurl.com]]>

If that doesn't help, please post a code sample from your dashboard.

0 Karma

georget
Explorer

Thanks, but It does not work. The Key Indicator Search complains about not using a valid path. I'd like to attach a snapshot from the form where the Key Indicator Search is defined, but I am not allowed. Once I set a CDATA value in the "Drilldown URL" fields of this custom search form, I get the message:
Defines the view to redirect users to when they click the key indicator. Must be a valid path.
The form the new Key Indicator's search is defined in, is in the Custom Searches page of the ES app. There is no custom dashboard. The new Key Indicator is attached to the top panel (with the rest of the indicators) of the Security Posture dashboard of the ES app.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...