Splunk Enterprise Security
Highlighted

After integrating a new Key Security Indicator in an Enterprise Security dashboard, how do I get the drilldown URL to point to a dashboard in my custom app?

Explorer

Hi,

I've created a new Key Security Indicator for my app and have integrated it in the Security Posture dashboard of the Splunk App for Enterprise Security. I'd like the drilldown url to point to one of the dashboards of my custom app. If I try to add a URL path with slashes in the Key Indicator Search form, it is not accepted. So is it possible to reference my dashboard from the indicator?

Thanks.

0 Karma
Highlighted

Re: After integrating a new Key Security Indicator in an Enterprise Security dashboard, how do I get the drilldown URL to point to a dashboard in my custom app?

Influencer

Encase your URL as character data:

<![CDATA[http://www.myurl.com]]>

If that doesn't help, please post a code sample from your dashboard.

0 Karma
Highlighted

Re: After integrating a new Key Security Indicator in an Enterprise Security dashboard, how do I get the drilldown URL to point to a dashboard in my custom app?

Explorer

Thanks, but It does not work. The Key Indicator Search complains about not using a valid path. I'd like to attach a snapshot from the form where the Key Indicator Search is defined, but I am not allowed. Once I set a CDATA value in the "Drilldown URL" fields of this custom search form, I get the message:
Defines the view to redirect users to when they click the key indicator. Must be a valid path.
The form the new Key Indicator's search is defined in, is in the Custom Searches page of the ES app. There is no custom dashboard. The new Key Indicator is attached to the top panel (with the rest of the indicators) of the Security Posture dashboard of the ES app.

0 Karma
Highlighted

Re: After integrating a new Key Security Indicator in an Enterprise Security dashboard, how do I get the drilldown URL to point to a dashboard in my custom app?

Explorer

I realized that if you edit savedsearches.conf and change the value of the "action.keyindicator.drilldown_uri" property of the Key Indicator search, you can specify whatever URL you want. For some reason this does not work through the Key Indicator Form in the web UI.

View solution in original post