Splunk Enterprise Security

Custom dashboards from a search

smelf1
Explorer

Hi,

I have a local admin search being sent to Splunk from Tenable IO. It lists all the machines (asset) name and each member of the local admin groups (Output).

An example of the output per asset would be below
The following users are members of the 'Administrators' group:
- --**\administrator (User)
- *
--*\ABC (User)

How can i get a dashboard to show every particular local admin listing all assets it has local admin access to.

Thanks

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...