Splunk Enterprise Security

Custom dashboards from a search

smelf1
Explorer

Hi,

I have a local admin search being sent to Splunk from Tenable IO. It lists all the machines (asset) name and each member of the local admin groups (Output).

An example of the output per asset would be below
The following users are members of the 'Administrators' group:
- --**\administrator (User)
- *
--*\ABC (User)

How can i get a dashboard to show every particular local admin listing all assets it has local admin access to.

Thanks

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...