Splunk Enterprise Security

Splunk Enterprise Security: How can I get Incident Review to refresh itself automatically?

LukeMurphey
Champion

I have Splunk Enterprise Security and I want Incident Review to refresh itself automatically. What is the best way to do this?

1 Solution

LukeMurphey
Champion

You can have Incident Review automatically update by running a real-time search. This will show updates automatically in real-time.

But I only want Incident Review to show notable events created from now on
Run an all-time real-time search if you want Incident Review to show all notable events that are created after the start the search. This works because an all-time real-time search doesn't back-fill; it will only show things coming in from now on.

But I want to show this on a big screen along with other dashboards
In this case, you may to consider using the Slideshow app. That app allows you to create shows consisting of a series of dashboards. It also supports a "dark-mode" that loos nice on a big-screen. Another option is using a browser plugin to cycle through dashboards.

View solution in original post

LukeMurphey
Champion

You can have Incident Review automatically update by running a real-time search. This will show updates automatically in real-time.

But I only want Incident Review to show notable events created from now on
Run an all-time real-time search if you want Incident Review to show all notable events that are created after the start the search. This works because an all-time real-time search doesn't back-fill; it will only show things coming in from now on.

But I want to show this on a big screen along with other dashboards
In this case, you may to consider using the Slideshow app. That app allows you to create shows consisting of a series of dashboards. It also supports a "dark-mode" that loos nice on a big-screen. Another option is using a browser plugin to cycle through dashboards.

Get Updates on the Splunk Community!

Buttercup Games: Further Dashboarding Techniques (Part 6)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Splunk Observability Synthetic Monitoring - Resolved Incident on Detector Alerts

We’ve discovered a bug that affected the auto-clear of Synthetic Detectors in the Splunk Synthetic Monitoring ...