Splunk Enterprise Security

Splunk Enterprise Security: Add a Filter to the Traffic Size Analysis Dashboard

itsmevic
Communicator

I'd like to add a filter to the Traffic Size Analysis Dashboard. The filter I'd like to add is the "src_ip" field. Currently, this dashboard doesn't allow you to search by one IP and I think having that filter would be very helpful. What would be the best way in going about and adding this?

Labels (1)
0 Karma

The_Simko
Path Finder

Hi. For ease, I'd click "clone" on the dashboard and make it a test page (that way you are working on a safe copy).  
Since it's a clone, you have edit rights. Click add input, add in the new filter dropdown. Be sure to have the default as "*" so you get everything, except when selecting the filter.  Then you'll need to edit the searches to have your new token (as assigned by your filter).  
If you are newer on dashboards, download the "dashboards example" app. There are examples there showing how to create inputs and how to send tokens.
  
Once you have this all worked out, you can edit the main page and paste it your SPL.

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...